#VU16491 Security restrictions bypass in Mozilla Firefox - CVE-2018-18496
Published: December 12, 2018
Vulnerability identifier: #VU16491
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-18496
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Mozilla Firefox
Mozilla Firefox
Software vendor:
Mozilla
Mozilla
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The weakness exists due to an error when the RSS Feed preview
The weakness exists due to an error when the RSS Feed preview
about:feeds page is framed within another page. A remote attacker can use the RSS Feed preview about:feeds page in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory.Remediation
Update to version 64.0.