Cross-site scripting in Mozilla Firefox - CVE-2018-5158
Published: May 10, 2018 / Updated: May 10, 2018
Vulnerability details
The vulnerability exists due to the PDF viewer does not sufficiently sanitize PostScript calculator functions. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks
Affected software
Firefox ESR
Gentoo Linux
Debian Linux
Arch Linux
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Siebel Industry - Life Sciences
How to mitigate CVE-2018-5158
External References
Related Security Bulletins
- Multiple vulnerabilities in Mozilla Firefox
- Multiple vulnerabilities in Mozilla Firefox ESR
- OpenSUSE Linux update for Mozilla Firefox
- Debian update for firefox-esr
- Arch Linux update for firefox
- Red Hat update for Mozilla Firefox
- Red Hat update for Mozilla Firefox
- Gentoo update for Mozilla Firefox
- Cross-site scripting in Siebel Industry - Life Sciences