Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5168

Опубликовано: 11 июн. 2018
Источник: debian

Описание

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
firefoxfixed60.0-1package
firefox-esrfixed52.8.0esr-1package
thunderbirdfixed1:52.8.0-1package

Примечания

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5168

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-12/#CVE-2018-5168

  • https://www.mozilla.org/en-US/security/advisories/mfsa2018-13/#CVE-2018-5168

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 7 лет назад

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 6.1
redhat
больше 7 лет назад

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 5.3
nvd
больше 7 лет назад

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 5.3
github
больше 3 лет назад

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 6.5
fstec
около 7 лет назад

Уязвимость компонента baseURI браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, позволяющая нарушителю оказать влияние на целостность защищаемой информации