UBUNTU-CVE-2018-18495
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-18495
UBUNTU-CVE-2018-18495
Summary:
Details: WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
References: https://ubuntu.com/security/CVE-2018-18495, https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/#CVE-2018-18495, https://ubuntu.com/security/notices/USN-3844-1, https://www.cve.org/CVERecord?id=CVE-2018-18495
Affected packages
Package
Name: firefox
Purl: pkg:deb/ubuntu/[email protected]+build3-0ubuntu0.14.04.1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
