First published: Tue Dec 11 2018(Updated: )
The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <64 | 64 |
<64 | 64 | |
Mozilla Firefox | <64.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
The vulnerability ID for this issue is CVE-2018-18510.
The severity of CVE-2018-18510 is medium.
Mozilla Firefox versions up to 64.0 are affected by CVE-2018-18510.
By linking to the about:crashcontent and about:crashparent pages, a malicious site can perform a non-persistent denial of service (DOS) attack.
You can find more information about CVE-2018-18510 in the following references: [link1](https://bugzilla.mozilla.org/show_bug.cgi?id=1507702), [link2](https://www.mozilla.org/en-US/security/advisories/mfsa2018-29/), [link3](https://www.mozilla.org/security/advisories/mfsa2018-29/).