CVE-2018-5109Origin Validation Error in Mozilla Firefox

Severity
5.3MEDIUMNVD
OSV9.8
EPSS
0.5%
top 35.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 14

Description

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages4 packages

debiandebian/firefox< firefox 58.0-1 (sid)
CVEListV5mozilla/firefoxunspecified58
Ubuntumozilla/firefox< 58.0.2+build1-0ubuntu0.14.04.1+4
NVDmozilla/firefox57.0.4

Also affects: Ubuntu Linux 14.04, 16.04, 17.10

🔴Vulnerability Details

4
GHSA
GHSA-3cvc-f83h-vhvc: An audio capture session can started under an incorrect origin from the site making the capture request2022-05-14
OSV
firefox regressions2018-02-12
OSV
firefox vulnerabilities2018-01-24
OSV
CVE-2018-5109: An audio capture session can started under an incorrect origin from the site making the capture request2018-01-23

📋Vendor Advisories

3
Ubuntu
Firefox regressions2018-02-12
Ubuntu
Firefox vulnerabilities2018-01-24
Debian
CVE-2018-5109: firefox - An audio capture session can started under an incorrect origin from the site mak...2018