The package firefox before version 61.0-1 is vulnerable to multiple issues including arbitrary code execution, cross-site request forgery, same-origin policy bypass, access restriction bypass and information disclosure.
Arch Linux Security Advisory ASA-201806-14
=========================================
Severity: Critical
Date : 2018-06-27
CVE-ID : CVE-2018-5186 CVE-2018-5187 CVE-2018-5188 CVE-2018-12356
CVE-2018-12358 CVE-2018-12359 CVE-2018-12360 CVE-2018-12361
CVE-2018-12362 CVE-2018-12363 CVE-2018-12364 CVE-2018-12365
CVE-2018-12366 CVE-2018-12367 CVE-2018-12369 CVE-2018-12370
CVE-2018-12371
Package : firefox
Type : multiple issues
Remote : Yes
Link : https://security.archlinux.org/AVG-727
Summary
======
The package firefox before version 61.0-1 is vulnerable to multiple
issues including arbitrary code execution, cross-site request forgery,
same-origin policy bypass, access restriction bypass and information
disclosure.
Resolution
=========
Upgrade to 61.0-1.
# pacman -Syu "firefox>=61.0-1"
The problems have been fixed upstream in version 61.0.
Workaround
=========
None.
Description
==========
- CVE-2018-5186 (arbitrary code execution)
Several memory safety bugs have been found in Firefox before 61.0. Some
of these bugs showed evidence of memory corruption and Mozilla presumes
that with enough effort some of these could be exploited to run
arbitrary code.
- CVE-2018-5187 (arbitrary code execution)
Several memory safety bugs have been found in Firefox before 61.0. Some
of these bugs showed evidence of memory corruption and Mozilla presumes
that with enough effort some of these could be exploited to run
arbitrary code.
- CVE-2018-5188 (arbitrary code execution)
Several memory safety bugs have been found in Firefox before 61.0. Some
of these bugs showed evidence of memory corruption and Mozilla presumes
that with enough effort some of these could be exploited to run
arbitrary code.
- CVE-2018-12356 (arbitrary code execution)
An issue was discovered in password-store.sh in pass in Simple Password
Store 1.7 through 1.7.1. The signature verification routine parses the
output of GnuPG with an incomplete regular expression, which allows
remote attackers to spoof file signatures on configuration files and
extensions scripts. Modifying the configuration file allows the
attacker to inject additional encryption keys under their control,
thereby disclosing passwords to the attacker. Modifying the extension
scripts allows the attacker arbitrary code execution.
- CVE-2018-12358 (same-origin policy bypass)
Service workers in Firefox before 61.0 can use redirection to avoid the
tainting of cross-origin resources in some instances, allowing a
malicious site to read responses which are supposed to be opaque.
- CVE-2018-12359 (arbitrary code execution)
A buffer overflow can occur in Firefox before 61.0 when rendering
canvas content while adjusting the height and width of the