PT-2018-16784 · Mozilla+1 · Firefox For Android+1

Rugk

·

Published

2018-03-27

·

Updated

2024-12-12

·

CVE-2018-5138

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 59
Description A spoofing issue can occur when a malicious site with a very long domain name is opened in an Android Custom Tab and the default browser is Firefox for Android. This could allow an attacker to spoof the page that is actually loaded and in use.
Recommendations For Firefox for Android versions prior to 59, update to version 59 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1502
CVE-2018-5138
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:14572-1

Affected Products

Alt Linux
Firefox For Android