CVE-2018-5118

MEDIUM
New! CVE Severity Now Using CVSS v3

The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.

Description

The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images through "file:" URLs from the local file system. This loading is blocked by the sandbox but could expose local data if combined with another attack that escapes sandbox protections. This vulnerability affects Firefox < 58.

References

http://www.securityfocus.com/bid/102786

http://www.securitytracker.com/id/1040270

https://bugzilla.mozilla.org/show_bug.cgi?id=1420049

https://usn.ubuntu.com/3544-1/

https://www.mozilla.org/security/advisories/mfsa2018-02/

Details

Source: MITRE

Published: 2018-06-11

Updated: 2018-06-25

Type: CWE-200

Risk Information

CVSS v2

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM

CVSS v3

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 3.9

Severity: MEDIUM

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
700326Mozilla Firefox < 58 Multiple VulnerabilitiesNessus Network MonitorWeb Clients
critical
106790Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : firefox regressions (USN-3544-2)NessusUbuntu Local Security Checks
critical
106347Ubuntu 14.04 LTS / 16.04 LTS / 17.10 : firefox vulnerabilities (USN-3544-1)NessusUbuntu Local Security Checks
critical
106303Mozilla Firefox < 58 Multiple VulnerabilitiesNessusWindows
critical
106301Mozilla Firefox < 58 Multiple Vulnerabilities (macOS)NessusMacOS X Local Security Checks
critical
106288FreeBSD : mozilla -- multiple vulnerabilities (a891c5b4-3d7a-4de9-9c71-eef3fd698c77)NessusFreeBSD Local Security Checks
critical