PT-2018-2991 · Mozilla+5 · Firefox+5
Wladimir Palant
·
Published
2018-05-09
·
Updated
2024-12-12
·
CVE-2018-5157
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox ESR versions prior to 52.8
Firefox versions prior to 60
Description
The issue allows a malicious site to bypass same-origin protections for the PDF viewer, potentially intercepting messages meant for the viewer. This could enable the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. The vulnerability is also described as being due to insufficient input validation in the Capture Handler component of Firefox ESR and Firefox browsers, which could allow a remote attacker to elevate their privileges.
Recommendations
For Firefox ESR versions prior to 52.8, update to version 52.8 or later.
For Firefox versions prior to 60, update to version 60 or later.
Fix
RCE
Information Disclosure
Origin Validation Error
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Firefox
Red Hat
Suse
Ubuntu