CVE-2018-18506
published 2019-02-05CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
2.18%
80.3th percentile
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | firefox | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | firefox-esr | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| debian | thunderbird | < firefox 65.0-1 (sid) | firefox 65.0-1 (sid) |
| mozilla | firefox | < 65.0 | 65.0 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.14.04.1 | 65.0+build2-0ubuntu0.14.04.1 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.16.04.1 | 65.0+build2-0ubuntu0.16.04.1 |
| mozilla | firefox | >= 0 < 65.0+build2-0ubuntu0.18.04.1 | 65.0+build2-0ubuntu0.18.04.1 |
| mozilla | firefox | >= unspecified < 65 | 65 |
| mozilla | thunderbird | >= 0 < 1:60.6.1-1 | 1:60.6.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1-1 | 1:60.6.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1-1 | 1:60.6.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1-1 | 1:60.6.1-1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1+build2-0ubuntu0.14.04.1 | 1:60.6.1+build2-0ubuntu0.14.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1+build2-0ubuntu0.16.04.1 | 1:60.6.1+build2-0ubuntu0.16.04.1 |
| mozilla | thunderbird | >= 0 < 1:60.6.1+build2-0ubuntu0.18.04.1 | 1:60.6.1+build2-0ubuntu0.18.04.1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4gc3-hqxg-hgp9: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file c
ghsa_unreviewed·2022-05-13
CVE-2018-18506 [MEDIUM] GHSA-4gc3-hqxg-hgp9: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file c
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
OSV
thunderbird vulnerabilities
osv·2019-03-28·CVSS 5.9
CVE-2018-18506 [MEDIUM] thunderbird vulnerabilities
thunderbird vulnerabilities
It was discovered that Thunderbird allowed PAC files to specify that
requests to localhost are sent through the proxy to another server. If
proxy auto-detection is enabled, an attacker could potentially exploit
this to conduct attacks on local services and tools. (CVE-2018-18506)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2019-9788, CVE-2019-9790, CVE-2019-9791,
CVE-2019-9792, CVE-2019-9795, CVE-2019-9796, CVE-2019-9810, CVE-2019-9813)
A mechanism was discovered that removes some bounds checking for string,
array, or typed array accesses if Spectre mitiga
OSV
CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file c
osv·2019-02-05·CVSS 5.9
CVE-2018-18506 [MEDIUM] CVE-2018-18506: When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file c
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
OSV
firefox vulnerabilities
osv·2019-01-30·CVSS 9.8
CVE-2018-18500 [CRITICAL] firefox vulnerabilities
firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, gain additional
privileges by escaping the sandbox, or execute arbitrary code.
(CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503,
CVE-2018-18504, CVE-2018-18505)
It was discovered that Firefox allowed PAC files to specify that requests
to localhost are sent through the proxy to another server. If proxy
auto-detection is enabled, an attacker could potentially exploit this to
conduct attacks on local services and tools. (CVE-2018-18506)
Ubuntu
Thunderbird vulnerabilities
vendor_ubuntu·2019-03-28·CVSS 5.9
CVE-2018-18506 [MEDIUM] Thunderbird vulnerabilities
Title: Thunderbird vulnerabilities
Summary: Several security issues were fixed in Thunderbird.
It was discovered that Thunderbird allowed PAC files to specify that
requests to localhost are sent through the proxy to another server. If
proxy auto-detection is enabled, an attacker could potentially exploit
this to conduct attacks on local services and tools. (CVE-2018-18506)
Multiple security issues were discovered in Thunderbird. If a user were
tricked in to opening a specially crafted website in a browsing context,
an attacker could potentially exploit these to cause a denial of service,
or execute arbitrary code. (CVE-2019-9788, CVE-2019-9790, CVE-2019-9791,
CVE-2019-9792, CVE-2019-9795, CVE-2019-9796, CVE-2019-9810, CVE-2019-9813)
A mechanism was discovered that removes some bounds c
Red Hat
Mozilla: Proxy Auto-Configuration file can define localhost access to be proxied
vendor_redhat·2019-03-20·CVSS 5.9
CVE-2018-18506 [MEDIUM] CWE-200 Mozilla: Proxy Auto-Configuration file can define localhost access to be proxied
Mozilla: Proxy Auto-Configuration file can define localhost access to be proxied
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2019-01-30·CVSS 9.8
CVE-2018-18500 [CRITICAL] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, gain additional
privileges by escaping the sandbox, or execute arbitrary code.
(CVE-2018-18500, CVE-2018-18501, CVE-2018-18502, CVE-2018-18503,
CVE-2018-18504, CVE-2018-18505)
It was discovered that Firefox allowed PAC files to specify that requests
to localhost are sent through the proxy to another server. If proxy
auto-detection is enabled, an attacker could potentially exploit this to
conduct attacks on local services and tools. (CVE-2018-18506)
Instructions: A
Debian
CVE-2018-18506: firefox - When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Config...
vendor_debian·2018·CVSS 5.9
CVE-2018-18506 [MEDIUM] CVE-2018-18506: firefox - When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Config...
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
Scope: local
sid: resolved (fixed in 65.0-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-03/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.htmlhttp://www.securityfocus.com/bid/106773https://access.redhat.com/errata/RHSA-2019:0622https://access.redhat.com/errata/RHSA-2019:0623https://access.redhat.com/errata/RHSA-2019:0680https://access.redhat.com/errata/RHSA-2019:0681https://access.redhat.com/errata/RHSA-2019:0966https://access.redhat.com/errata/RHSA-2019:1144https://lists.debian.org/debian-lts-announce/2019/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00000.htmlhttps://seclists.org/bugtraq/2019/Apr/0https://seclists.org/bugtraq/2019/Mar/28https://security.gentoo.org/glsa/201904-07https://usn.ubuntu.com/3874-1/https://usn.ubuntu.com/3927-1/https://www.debian.org/security/2019/dsa-4411https://www.debian.org/security/2019/dsa-4420https://www.mozilla.org/security/advisories/mfsa2019-01/http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00035.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-03/msg00043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.htmlhttp://www.securityfocus.com/bid/106773https://access.redhat.com/errata/RHSA-2019:0622https://access.redhat.com/errata/RHSA-2019:0623https://access.redhat.com/errata/RHSA-2019:0680https://access.redhat.com/errata/RHSA-2019:0681https://access.redhat.com/errata/RHSA-2019:0966https://access.redhat.com/errata/RHSA-2019:1144https://lists.debian.org/debian-lts-announce/2019/03/msg00024.htmlhttps://lists.debian.org/debian-lts-announce/2019/04/msg00000.htmlhttps://seclists.org/bugtraq/2019/Apr/0https://seclists.org/bugtraq/2019/Mar/28https://security.gentoo.org/glsa/201904-07https://usn.ubuntu.com/3874-1/https://usn.ubuntu.com/3927-1/https://www.debian.org/security/2019/dsa-4411https://www.debian.org/security/2019/dsa-4420https://www.mozilla.org/security/advisories/mfsa2019-01/
2019-02-05
Published