Improper input validation in Mozilla Firefox - CVE-2018-5124
Published: January 29, 2018 / Updated: January 30, 2018
Vulnerability identifier: #VU10327
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-5124
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Mozilla
Affected software:
Mozilla Firefox
Mozilla Firefox
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to absent sanitization of the output in the browser UI when processing HTML fragments created for chrome-privileged documents. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the target system.
The vulnerability exists due to absent sanitization of the output in the browser UI when processing HTML fragments created for chrome-privileged documents. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the target system.
How to mitigate CVE-2018-5124
Update to version 58.0.1.