logo

CVE-2018-5158 pdfjs-dist

Package

Manager: npm
Name: pdfjs-dist
Vulnerable Version: >=2.0.0 <2.0.550 || >=0 <1.10.100

Severity

Level: High

CVSS v3.1: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

EPSS: 0.55527 pctl0.97995

Details

Malicious PDF can inject JavaScript into PDF Viewer The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8, Firefox < 60 and PDF.js < 2.0.550.

Metadata

Created: 2022-05-14T01:22:02Z
Modified: 2024-05-28T20:43:53Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7jg2-jgv3-fmr4/GHSA-7jg2-jgv3-fmr4.json
CWE IDs: ["CWE-94"]
Alternative ID: GHSA-7jg2-jgv3-fmr4
Finding: F422
Auto approve: 1