When proxy auto-detection is enabled, if a web server serves...
Vulnerability Description
When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-18506
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.mozilla.org/security/advisories/mfsa2019-01/
- http://www.securityfocus.com/bid/106773
- https://usn.ubuntu.com/3874-1/
- https://access.redhat.com/errata/RHSA-2019:0623
- https://access.redhat.com/errata/RHSA-2019:0622
- https://seclists.org/bugtraq/2019/Mar/28
- https://www.debian.org/security/2019/dsa-4411
- https://lists.debian.org/debian-lts-announce/2019/03/msg00024.html
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00035.html
- https://access.redhat.com/errata/RHSA-2019:0680
- https://access.redhat.com/errata/RHSA-2019:0681
- https://usn.ubuntu.com/3927-1/
- http://lists.opensuse.org/opensuse-security-announce/2019-03/msg00043.html
- https://www.debian.org/security/2019/dsa-4420
- https://seclists.org/bugtraq/2019/Apr/0
- https://lists.debian.org/debian-lts-announce/2019/04/msg00000.html
- https://security.gentoo.org/glsa/201904-07
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00023.html
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00043.html
- https://access.redhat.com/errata/RHSA-2019:0966
- https://access.redhat.com/errata/RHSA-2019:1144
More from Mozilla
View All →Affected Vendor
Mozilla
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.