VDB
CVE-2018-5163
CVE-2018-5163
PUBLISHED
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
EPSS 1.98% · 83.9th percentile
Risk Scores
EPSS Score
1.98%
83.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | firefox | 0, 24.0+build1-0ubuntu1, 28.0~b2+build1-0ubuntu2 |
| Ubuntu:16.04:LTS | firefox | 0, 41.0.2+build2-0ubuntu1, 42.0+build2-0ubuntu1 |
| Ubuntu:18.04:LTS | firefox | 0, 56.0+build6-0ubuntu1, 57.0.1+build2-0ubuntu1 |
Timeline
- May 11, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
- Mar 11, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-5163 third-party-advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/#CVE-2018-5163 third-party-advisory
- https://ubuntu.com/security/notices/USN-3645-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-5163 third-party-advisory