CVE-2018-5158 PUBLISHED

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

EPSS 41.38% · 97.4th percentile

Risk Scores

EPSS Score
41.38%
97.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfirefox0, 56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1
Ubuntu:16.04:LTSfirefox44.0.2+build1-0ubuntu1, 45.0+build2-0ubuntu1, 45.0.1+build1-0ubuntu1
Ubuntu:14.04:LTSfirefox50.1.0+build2-0ubuntu0.14.04.1, 51.0.1+build2-0ubuntu0.14.04.1, 51.0.1+build2-0ubuntu0.14.04.2

Timeline

References

Open in Interactive Console →