PT-2017-3680 · Mozilla+2 · Firefox+2

Andreas Pehrson

·

Published

2017-10-04

·

Updated

2024-12-12

·

CVE-2018-5109

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Mozilla Firefox versions prior to 58
Description: The issue is related to a flaw in the source confirmation mechanism, potentially allowing a remote attacker to gain unauthorized access to protected information. An audio capture session can be started under an incorrect origin, leading to user confusion about which site is making the request to capture an audio stream. Users are still prompted to allow the request, but the prompt may display the wrong origin.
Recommendations: For versions prior to 58, update to version 58 or later to resolve the issue. As a temporary workaround, consider restricting access to audio capture sessions to minimize the risk of exploitation. Avoid allowing audio capture requests from untrusted sites until the issue is resolved.

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1178
ALT-PU-2018-1854
BDU:2018-00873
CVE-2018-5109
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1
USN-3544-1
USN-3544-2

Affected Products

Alt Linux
Firefox
Ubuntu