CVE-2018-5173: Canonical Ubuntu Linux

Medium severity, CVSS 5.3. EPSS: 1.8% chance of exploitation in the next 30 days.

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Mozilla Firefox: before 60.0 (fixed in 60.0)

Published 2018-06-11. Last modified 2026-06-17.