Improper input validation in Mozilla Firefox - CVE-2018-5124
Published: January 29, 2018 / Updated: January 30, 2018
Vulnerability identifier: #VU10327
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5124
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to absent sanitization of the output in the browser UI when processing HTML fragments created for chrome-privileged documents. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the target system.
The vulnerability exists due to absent sanitization of the output in the browser UI when processing HTML fragments created for chrome-privileged documents. A remote attacker can create a specially crafted web page, trick the victim into opening it and execute arbitrary code on the target system.
Affected software
Mozilla Firefox
Ubuntu
Ubuntu
How to mitigate CVE-2018-5124
Update to version 58.0.1.