CVE-2018-5182: Infoleak
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent "file:" URL. This vulnerability affects Firefox < 60.
Other sources
If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy and is what would happen if the string were the equivalent file: URL.
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2018-5154
- CVE-2018-5155
- CVE-2018-5157
- CVE-2018-5158
- CVE-2018-5159
- CVE-2018-5160
- CVE-2018-5152
- CVE-2018-5153
- CVE-2018-5163
- CVE-2018-5164
- CVE-2018-5166
- CVE-2018-5167
- CVE-2018-5168
- CVE-2018-5169
- CVE-2018-5172
- CVE-2018-5173
- CVE-2018-5174
- CVE-2018-5175
- CVE-2018-5176
- CVE-2018-5177
- CVE-2018-5165
- CVE-2018-5180
- CVE-2018-5181
- CVE-2018-5182
- CVE-2018-5179
- CVE-2018-5151
- CVE-2018-5150
Frequently Asked Questions
What is CVE-2018-5182?
CVE-2018-5182 is a vulnerability in Mozilla Firefox where dragging and dropping a text string that happens to be a filename onto the address bar can open a specified local file, contrary to policy.
What is the severity of CVE-2018-5182?
CVE-2018-5182 has a severity rating of high with a CVSS score of 7.5.
Which versions of Mozilla Firefox are affected by CVE-2018-5182?
Mozilla Firefox versions up to but excluding 60.0 are affected by CVE-2018-5182.
How can I fix the vulnerability CVE-2018-5182?
To fix CVE-2018-5182, update Mozilla Firefox to version 60.0 or later.
What is the reference for CVE-2018-5182?
The references for CVE-2018-5182 are: - [Mozilla Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1435908) - [Mozilla Security Advisory](https://www.mozilla.org/en-US/security/advisories/mfsa2018-11/) - [SecurityFocus](http://www.securityfocus.com/bid/104139)