CVE-2018-5163Improper Preservation of Permissions in Mozilla Firefox

Severity
8.1HIGHNVD
OSV9.8
EPSS
2.0%
top 16.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 11
Latest updateMay 13

Description

If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages4 packages

debiandebian/firefox< firefox 60.0-1 (sid)
CVEListV5mozilla/firefoxunspecified60
NVDmozilla/firefox< 60.0
Ubuntumozilla/firefox< 60.0+build2-0ubuntu0.14.04.1+5

Also affects: Ubuntu Linux 14.04, 16.04, 17.10, 18.04

🔴Vulnerability Details

4
GHSA
GHSA-647q-gc86-99gj: If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data res2022-05-13
OSV
firefox regression2018-05-18
OSV
firefox vulnerabilities2018-05-11
OSV
CVE-2018-5163: If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data res2018-05-11

📋Vendor Advisories

4
Ubuntu
Firefox regression2018-05-18
Ubuntu
Firefox vulnerabilities2018-05-11
Red Hat
Mozilla: Replacing cached data in JavaScript Start-up Bytecode Cache2018-05-09
Debian
CVE-2018-5163: firefox - If a malicious attacker has used another vulnerability to gain full control over...2018

💬Community

1
Bugzilla
CVE-2018-5163 Mozilla: Replacing cached data in JavaScript Start-up Bytecode Cache2018-05-09