Information disclosure in Mozilla Firefox - CVE-2018-5182
Published: May 10, 2018
Vulnerability identifier: #VU12572
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-5182
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.
The weakness exists due to improper privileges or access controls. A remote attacker can drag and drop a text string that happens to be a filename in the operating system's native format onto the addressbar and cause the system to display local files in tabs.
Affected software
Mozilla Firefox
Arch Linux
Arch Linux
How to mitigate CVE-2018-5182
Update to version 60.0.