CVE-2018-12402

Priority
Description
The internal WebBrowserPersist code does not use correct origin context for
a resource being saved. This manifests when sub-resources are loaded as
part of "Save Page As..." functionality. For example, a malicious page
could recover a visitor's Windows username and NTLM hash by including
resources otherwise unreachable to the malicious page, if they can convince
the visitor to save the complete web page. Similarly, SameSite cookies are
sent on cross-origin requests when the "Save Page As..." menu item is
selected to save a page, which can result in saving the wrong version of
resources based on those cookies. This vulnerability affects Firefox < 63.
Notes
 tyhicks> mozjs contains a copy of the SpiderMonkey JavaScript engine
Assigned-to
chrisccoulson
Package
Upstream:released (63.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (63.0+build2-0ubuntu0.14.04.2)
Ubuntu 16.04 LTS (Xenial Xerus):released (63.0+build2-0ubuntu0.16.04.2)
Ubuntu 18.04 LTS (Bionic Beaver):released (63.0+build2-0ubuntu0.18.04.2)
Ubuntu 18.10 (Cosmic Cuttlefish):released (63.0+build2-0ubuntu0.18.10.2)
Ubuntu 19.04 (Disco Dingo):released (63.0+build1-0ubuntu1)
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):DNE
Ubuntu 19.04 (Disco Dingo):DNE
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):needs-triage
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
Package
Upstream:needs-triage
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):DNE
Ubuntu 16.04 LTS (Xenial Xerus):DNE
Ubuntu 18.04 LTS (Bionic Beaver):DNE
Ubuntu 18.10 (Cosmic Cuttlefish):needs-triage
Ubuntu 19.04 (Disco Dingo):needs-triage
More Information

Updated: 2019-03-19 11:28:00 UTC (commit 15472795df7e9de45b82f2d36b8b419b939f97b2)