CVE-2018-5118: Infoleak
Last updated 24 July 2024
Other sources
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images through "file:" URLs from the local file system. This loading is blocked by the sandbox but could expose local data if combined with another attack that escapes sandbox protections. This vulnerability affects Firefox < 58.
— Launchpad
The screenshot images displayed in the Activity Stream page displayed when a new tab is opened is created from the meta tags of websites. An issue was discovered where the page could attempt to create these images through file: URLs from the local file system. This loading is blocked by the sandbox but could expose local data if combined with another attack that escapes sandbox protections.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5091
- CVE-2018-5092
- CVE-2018-5093
- CVE-2018-5094
- CVE-2018-5095
- CVE-2018-5097
- CVE-2018-5098
- CVE-2018-5099
- CVE-2018-5100
- CVE-2018-5101
- CVE-2018-5102
- CVE-2018-5103
- CVE-2018-5104
- CVE-2018-5105
- CVE-2018-5106
- CVE-2018-5107
- CVE-2018-5108
- CVE-2018-5109
- CVE-2018-5110
- CVE-2018-5111
- CVE-2018-5112
- CVE-2018-5113
- CVE-2018-5114
- CVE-2018-5115
- CVE-2018-5116
- CVE-2018-5117
- CVE-2018-5118
- CVE-2018-5119
- CVE-2018-5121
- CVE-2018-5122
- CVE-2018-5090
- CVE-2018-5089
Frequently Asked Questions
What is CVE-2018-5118?
CVE-2018-5118 is a vulnerability in Mozilla Firefox that allows the loading of 'file:' URLs from the local file system on the Activity Stream page when a new tab is opened.
How severe is CVE-2018-5118?
CVE-2018-5118 has a severity score of 5.3 (medium).
Which software versions are affected by CVE-2018-5118?
Mozilla Firefox versions up to but excluding 58.0 are affected by CVE-2018-5118.
How can I fix CVE-2018-5118?
To fix CVE-2018-5118, update Mozilla Firefox to version 58.0 or later.
Where can I find more information about CVE-2018-5118?
You can find more information about CVE-2018-5118 on the Mozilla Bugzilla and Mozilla Security Advisories websites.