CVE-2018-5142 Information

Description

If Media Capture and Streams API permission is requested from documents with \data:\ or \blob:\ URLs the permission notifications do not properly display the originating domain. The notification states \Unknown protocol\ as the requestee leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox 59.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Reference

http://www.securityfocus.com/bid/103386 http://www.securitytracker.com/id/1040514 https://bugzilla.mozilla.org/show_bug.cgi?id=1366357 https://usn.ubuntu.com/3596-1/ https://www.mozilla.org/security/advisories/mfsa2018-06/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

5.3

Share on: