CVE-2018-5158: Code Injection
Last updated 24 July 2024
Other sources
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker.
— Mozilla
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
- CVE-2018-5183
- CVE-2018-5178
Frequently Asked Questions
What is CVE-2018-5158?
CVE-2018-5158 is a vulnerability in the PDF viewer of Firefox ESR < 52.8 and Firefox < 60 that allows malicious JavaScript to be injected through a crafted PDF file.
How does CVE-2018-5158 affect Firefox?
CVE-2018-5158 affects Firefox ESR < 52.8 and Firefox < 60, allowing malicious JavaScript to be injected through a crafted PDF file.
What is the severity of CVE-2018-5158?
CVE-2018-5158 has a severity value of 8.8, which is considered high.
How can I fix CVE-2018-5158?
To fix CVE-2018-5158, you should update your Firefox browser to version 52.8 or higher.
Where can I find more information about CVE-2018-5158?
You can find more information about CVE-2018-5158 at the following references: [Link 1](https://bugzilla.mozilla.org/show_bug.cgi?id=1452075), [Link 2](https://www.mozilla.org/security/advisories/mfsa2018-11/), [Link 3](https://www.mozilla.org/security/advisories/mfsa2018-12/)