Your submission was sent successfully! Close

CVE-2018-5172

Published: 11 May 2018

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

Priority

Medium

CVSS 3 base score: 4.3

Status

Package Release Status
firefox
Launchpad, Ubuntu, Debian
artful
Released (60.0+build2-0ubuntu0.17.10.1)
bionic
Released (60.0+build2-0ubuntu1)
precise Does not exist

trusty Does not exist
(trusty was released [60.0+build2-0ubuntu0.14.04.1])
upstream
Released (60.0)
xenial
Released (60.0+build2-0ubuntu0.16.04.1)