ASA-2019-00442 – Mozilla Firefox: Domain spoofing through unicode latin ‘kra’ character


Allele Security Alert

ASA-2019-00442

Identifier(s)

ASA-2019-00442, CVE-2019-11721, MFSA2019-21

Title

Domain spoofing through unicode latin ‘kra’ character

Vendor(s)

Mozilla

Product(s)

Mozilla Firefox

Affected version(s)

Mozilla Firefox version before 68

Fixed version(s)

Mozilla Firefox version 68

Proof of concept

Unknown

Description

The unicode latin ‘kra’ character can be used to spoof a standard ‘k’ character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion.

Technical details

Unknown

Credits

Unknown

Reference(s)

Mozilla Foundation Security Advisory 2019-21
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11721

(punycode) homograph attacks with Κʻ / ĸ (U+0138, *Kra*)
https://bugzilla.mozilla.org/show_bug.cgi?id=1256009

CVE-2019-11721
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11721

CVE-2019-11721
https://nvd.nist.gov/vuln/detail/CVE-2019-11721

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 18, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.