CVE-2018-5163
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-281
- Affected
- canonical/ubuntu linux · mozilla/firefox
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1426353Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
- http://www.securityfocus.com/bid/104139Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://bugzilla.mozilla.org/show_bug.cgi?id=1426353Issue Tracking, Permissions Required, Vendor Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.