Security restrictions bypass in Mozilla Firefox - CVE-2018-12381
Published: September 6, 2018
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to an error when the message's mail columns are incorrectly interpreted as a URL. A remote unauthenticated attacker can drag and drop an Outlook email message into the browser and trigger a page navigation.
Affected software
Firefox ESR
Gentoo Linux
How to mitigate CVE-2018-12381
Firefox ESR - update to 60.2.0