CVE-2018-5107Link Following in Mozilla Firefox

CWE-59Link Following8 documents5 sources
Severity
5.3MEDIUMNVD
OSV9.8
EPSS
1.2%
top 21.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. This vulnerability affects Firefox < 58.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/firefox< firefox 58.0-1 (sid)
CVEListV5mozilla/firefoxunspecified58
Ubuntumozilla/firefox< 58.0.2+build1-0ubuntu0.14.04.1+4
NVDmozilla/firefox57.0.4

Also affects: Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

4
GHSA
GHSA-gh9h-87wv-w3qc: The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions2022-05-14
OSV
firefox regressions2018-02-12
OSV
firefox vulnerabilities2018-01-24
OSV
CVE-2018-5107: The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions2018-01-23

📋Vendor Advisories

3
Ubuntu
Firefox regressions2018-02-12
Ubuntu
Firefox vulnerabilities2018-01-24
Debian
CVE-2018-5107: firefox - The printing process can bypass local access protections to read files available...2018