CVE-2018-5108

A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
References
Link Resource
https://www.mozilla.org/security/advisories/mfsa2018-02/ Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1421099 Issue Tracking Permissions Required
https://usn.ubuntu.com/3544-1/ Third Party Advisory
http://www.securitytracker.com/id/1040270 VDB Entry Third Party Advisory
http://www.securityfocus.com/bid/102786 Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*

Information

Published : 2018-06-11 14:29

Updated : 2018-06-25 10:39


NVD link : CVE-2018-5108

Mitre link : CVE-2018-5108


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

mozilla

  • firefox

canonical

  • ubuntu_linux