CVE-2018-5107
Last modified
CVE-2018-5107 is a vulnerability of currently unknown severity. The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. This vulnerability affects Firefox < 58.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | <= 57.0.4 |
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
References
- http://www.securityfocus.com/bid/102786Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040270Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1379276Issue Tracking, Permissions Required
- https://usn.ubuntu.com/3544-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-02/Vendor Advisory
- http://www.securityfocus.com/bid/102786Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040270Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1379276Issue Tracking, Permissions Required
- https://usn.ubuntu.com/3544-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-02/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5107?
How severe is CVE-2018-5107?
How do I fix CVE-2018-5107?
Are you affected by CVE-2018-5107?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
