Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18511

Опубликовано: 26 апр. 2019
Источник: debian

Описание

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed65.0.1-1package
firefox-esrfixed60.7.0esr-1package
thunderbirdfixed1:60.7.0-1package
skiaitppackage

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-04/#CVE-2018-18511

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-14/#CVE-2018-18511

  • https://www.mozilla.org/en-US/security/advisories/mfsa2019-15/#CVE-2018-18511

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 6 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
redhat
больше 6 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
nvd
больше 6 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
github
около 3 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 3.1
fstec
больше 6 лет назад

Уязвимость метода TransferFromImageBitmap почтового клиента Thunderbird и браузеров Firefox и Firefox ESR, связанная с возможностью чтения элемента canvas, игнорируя политику безопасности, позволяющая нарушителю получить несанкционированный доступ к информации