HIGH8.8
GHSA-7jg2-jgv3-fmr4
Malicious PDF can inject JavaScript into PDF Viewer
Quick fix
GHSA-7jg2-jgv3-fmr4 — pdfjs-dist: upgrade to the fixed version with the command below.
npm install pdfjs-dist@2.0.550Details
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8, Firefox < 60 and PDF.js < 2.0.550.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-5158[ADVISORY]
- https://github.com/mozilla/pdf.js/pull/9659[WEB]
- https://github.com/mozilla/pdf.js/commit/2dc4af525d1612c98afcd1e6bee57d4788f78f97[WEB]
- https://access.redhat.com/errata/RHSA-2018:1414[WEB]
- https://access.redhat.com/errata/RHSA-2018:1415[WEB]
- https://bugzilla.mozilla.org/show_bug.cgi?id=1452075[WEB]
- https://github.com/mozilla/pdf.js[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2018/05/msg00007.html[WEB]
- https://security.gentoo.org/glsa/201810-01[WEB]
- https://usn.ubuntu.com/3645-1[WEB]
- https://www.debian.org/security/2018/dsa-4199[WEB]
- https://www.mozilla.org/security/advisories/mfsa2018-11[WEB]
- https://www.mozilla.org/security/advisories/mfsa2018-12[WEB]
- http://www.securityfocus.com/bid/104136[WEB]
- http://www.securitytracker.com/id/1040896[WEB]