Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-5158

Опубликовано: 09 мая 2018
Источник: redhat
CVSS3: 8.8
EPSS Средний

Описание

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6thunderbirdNot affected
Red Hat Enterprise Linux 7thunderbirdNot affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 6firefoxFixedRHSA-2018:141414.05.2018
Red Hat Enterprise Linux 7firefoxFixedRHSA-2018:141514.05.2018

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-95
https://bugzilla.redhat.com/show_bug.cgi?id=1576259Mozilla: Malicious PDF can inject JavaScript into PDF Viewer

EPSS

Процентиль: 97%
0.31648
Средний

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 8.8
nvd
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 8.8
debian
больше 7 лет назад

The PDF viewer does not sufficiently sanitize PostScript calculator fu ...

CVSS3: 8.8
github
больше 3 лет назад

Malicious PDF can inject JavaScript into PDF Viewer

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость компонента PDF Viewer браузеров Firefox ESR и Firefox, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 97%
0.31648
Средний

8.8 High

CVSS3