VulnerabilityModified
CVE-2018-5142
This vulnerability affects Firefox < 59.
MEDIUM 5.3EPSS 1.21%
Does this matter?
Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.
Description
If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.21% probability · 67th percentile
- CISA KEV
- Not listed
- Affected
- mozilla/firefox · canonical/ubuntu linux
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/103386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040514Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1366357Permissions Required
- https://usn.ubuntu.com/3596-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-06/Vendor Advisory
- http://www.securityfocus.com/bid/103386Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040514Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1366357Permissions Required
- https://usn.ubuntu.com/3596-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-06/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.