5.9
CVE-2018-18506
- EPSS 2.18%
- Veröffentlicht 05.02.2019 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:56:04
- Erkennungen
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Desktop Version 6.0
Redhat ≫ Enterprise Linux Desktop Version 7.0
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Server Version 6.0
Redhat ≫ Enterprise Linux Server Version 7.0
Redhat ≫ Enterprise Linux Server Aus Version 7.6
Redhat ≫ Enterprise Linux Server Aus Version 8.2
Redhat ≫ Enterprise Linux Server Aus Version 8.4
Redhat ≫ Enterprise Linux Server Aus Version 8.6
Redhat ≫ Enterprise Linux Server Eus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 7.6
Redhat ≫ Enterprise Linux Server Tus Version 8.2
Redhat ≫ Enterprise Linux Server Tus Version 8.4
Redhat ≫ Enterprise Linux Server Tus Version 8.6
Redhat ≫ Enterprise Linux Workstation Version 6.0
Redhat ≫ Enterprise Linux Workstation Version 7.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.18% | 0.8 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
https://security.gentoo.org/glsa/201904-07
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.html
https://access.redhat.com/errata/RHSA-2019:1144
https://usn.ubuntu.com/3874-1/
https://www.mozilla.org/security/advisories/mfsa2019-01/
http://www.securityfocus.com/bid/106773
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00035.html
http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00043.html
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00023.html
https://access.redhat.com/errata/RHSA-2019:0622
https://access.redhat.com/errata/RHSA-2019:0623
https://access.redhat.com/errata/RHSA-2019:0680
https://access.redhat.com/errata/RHSA-2019:0681
https://access.redhat.com/errata/RHSA-2019:0966
https://lists.debian.org/debian-lts-announce/2019/03/msg00024.html
https://lists.debian.org/debian-lts-announce/2019/04/msg00000.html
https://seclists.org/bugtraq/2019/Apr/0
https://seclists.org/bugtraq/2019/Mar/28
https://usn.ubuntu.com/3927-1/
https://www.debian.org/security/2019/dsa-4411
https://www.debian.org/security/2019/dsa-4420