VulnerabilityModified
CVE-2018-5168
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element.
MEDIUM 5.3EPSS 2.38%
Does this matter?
Lower severity and a low EPSS score (2.38%). Track it; it rarely justifies an emergency change on its own.
Description
Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.38% probability · 83th percentile
- CISA KEV
- Not listed
- Affected
- debian/debian linux · mozilla/firefox · mozilla/thunderbird · mozilla/thunderbird esr · canonical/ubuntu linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- security@mozilla.org
References
- http://www.securityfocus.com/bid/104136Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1414Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1415Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1725Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1726Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1449548Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00007.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
- https://usn.ubuntu.com/3660-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4199Third Party Advisory
- https://www.debian.org/security/2018/dsa-4209Third Party Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-11/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-12/Vendor Advisory
- https://www.mozilla.org/security/advisories/mfsa2018-13/Vendor Advisory
- http://www.securityfocus.com/bid/104136Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040896Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:1414Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1415Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1725Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1726Third Party Advisory
- https://bugzilla.mozilla.org/show_bug.cgi?id=1449548Issue Tracking, Permissions Required, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00007.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/05/msg00013.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201810-01Third Party Advisory
- https://security.gentoo.org/glsa/201811-13Third Party Advisory
- https://usn.ubuntu.com/3645-1/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.