CVE-2019-11721

Source
Severity Medium
Remote Yes
Type Content spoofing
Description
The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar in Firefox before 68.0. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion.
Group Package Affected Fixed Severity Status Ticket
AVG-1002 firefox 67.0.4-2 68.0-1 Critical Fixed
Date Advisory Group Package Severity Description
17 Jul 2019 ASA-201907-4 AVG-1002 firefox Critical multiple issues
References
https://www.mozilla.org/en-US/security/advisories/mfsa2019-21/#CVE-2019-11721
https://bugzilla.mozilla.org/show_bug.cgi?id=1256009