First published: Tue Mar 13 2018(Updated: )
Last updated 24 July 2024
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox | <59 | 59 |
Mozilla Firefox | <59.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
debian/firefox | 131.0.2-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Found alongside the following vulnerabilities)
CVE-2018-5143 is a vulnerability in Mozilla Firefox where the protocol is not removed from a 'javascript:' URL if it contains a tab character, allowing the execution of scripts.
The severity of CVE-2018-5143 is medium with a CVSS score of 6.1.
Mozilla Firefox versions up to and exclusive of 59.0, Canonical Ubuntu Linux 14.04, 16.04, and 17.10.
Update Mozilla Firefox to version 59.0 or higher.
You can find more information about CVE-2018-5143 at the following links: [Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1422643), [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2018-06/), [SecurityFocus](http://www.securityfocus.com/bid/103386).