CVE-2018-5163
Last modified
CVE-2018-5163 is a vulnerability of currently unknown severity. If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 17.10 |
| Canonical | Ubuntu Linux | 18.04 |
| Mozilla | Firefox | < 60.0 |
References
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1426353Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1426353Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-5163?
How severe is CVE-2018-5163?
How do I fix CVE-2018-5163?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-5157Same-origin protections for the PDF viewer can be bypassed, …
- CVE-2018-5158The PDF viewer does not sufficiently sanitize PostScript cal…
- CVE-2018-5159An integer overflow can occur in the Skia library due to 32-…
- CVE-2018-5160WebRTC can use a "WrappedI420Buffer" pixel buffer but the ow…
- CVE-2018-5161Crafted message headers can cause a Thunderbird process to h…
- CVE-2018-5162Plaintext of decrypted emails can leak through the src attri…
- CVE-2018-5164Content Security Policy (CSP) is not applied correctly to al…
- CVE-2018-5165In 32-bit versions of Firefox, the Adobe Flash plugin settin…5.3
- CVE-2018-5166WebExtensions can use request redirection and a "filterRepon…
- CVE-2018-5167The web console and JavaScript debugger do not sanitize all …
- CVE-2018-5168Sites can bypass security checks on permissions to install l…
- CVE-2018-5169If manipulated hyperlinked text with "chrome:" URL contained…
Are you affected by CVE-2018-5163?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
