Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5158

Опубликовано: 11 июн. 2018
Источник: debian
EPSS Средний

Описание

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed60.0-1package
firefox-esrfixed52.8.0esr-1package
gitlabfixed11.8.6+dfsg-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5158

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5158

  • https://about.gitlab.com/2019/04/01/security-release-gitlab-11-dot-9-dot-4-released/

EPSS

Процентиль: 97%
0.31648
Средний

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 8.8
redhat
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 8.8
nvd
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 8.8
github
больше 3 лет назад

Malicious PDF can inject JavaScript into PDF Viewer

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость компонента PDF Viewer браузеров Firefox ESR и Firefox, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.31648
Средний