CVE-2018-5105Mozilla Firefox vulnerability

8 documents5 sources
Severity
7.8HIGHNVD
OSV9.8
EPSS
0.1%
top 79.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

debiandebian/firefox< firefox 58.0-1 (sid)
CVEListV5mozilla/firefoxunspecified58
Ubuntumozilla/firefox< 58.0.2+build1-0ubuntu0.14.04.1+4
NVDmozilla/firefox57.0.4

Also affects: Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

4
GHSA
GHSA-fq4p-86v9-5w3x: WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file2022-05-13
OSV
firefox regressions2018-02-12
OSV
firefox vulnerabilities2018-01-24
OSV
CVE-2018-5105: WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file2018-01-23

📋Vendor Advisories

3
Ubuntu
Firefox regressions2018-02-12
Ubuntu
Firefox vulnerabilities2018-01-24
Debian
CVE-2018-5105: firefox - WebExtensions can bypass user prompts to first save and then open an arbitrarily...2018