CVE-2018-5112

Priority
Medium
Description
Development Tools panels of an extension are required to load URLs for the
panels as relative URLs from the extension manifest file but this
requirement was not enforced in all instances. This could allow the
development tools panel for the extension to load a URL that it should not
be able to access, including potentially privileged pages. This
vulnerability affects Firefox < 58.
References
Assigned-to
chrisccoulson
Package
Upstream:released (58.0)
Ubuntu 12.04 ESM (Precise Pangolin):DNE
Ubuntu 14.04 LTS (Trusty Tahr):released (58.0+build6-0ubuntu0.14.04.1)
Ubuntu 16.04 LTS (Xenial Xerus):released (58.0+build6-0ubuntu0.16.04.1)
Ubuntu 17.10 (Artful Aardvark):released (58.0+build6-0ubuntu0.17.10.1)
Ubuntu 18.04 LTS (Bionic Beaver):released (59.0.1+build1-0ubuntu1)
Ubuntu 18.10 (Cosmic Cuttlefish):released (59.0.1+build1-0ubuntu1)
More Information

Updated: 2018-06-13 17:15:54 UTC (commit 14944)