CVE-2018-5163: High severity ubuntu vulnerability
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5163?
CVE-2018-5163 is a vulnerability that allows a malicious attacker to replace JavaScript code in the JavaScript Start-up Bytecode Cache (JSBC) in Mozilla Firefox.
How does CVE-2018-5163 impact users?
CVE-2018-5163 allows attackers to execute arbitrary JavaScript code if the parent process runs the replaced code.
What is the severity of CVE-2018-5163?
CVE-2018-5163 has a severity rating of 8.1 (High).
Which software versions are affected by CVE-2018-5163?
Mozilla Firefox versions up to and excluding 60.0 are affected by CVE-2018-5163.
How can I fix CVE-2018-5163?
Update to Mozilla Firefox version 60.0 or higher to fix CVE-2018-5163.