PT-2018-3039 · Mozilla+2 · Firefox Esr+4
Jun Kokatsu
·
Published
2018-06-26
·
Updated
2024-12-12
·
CVE-2018-12391
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Firefox for Android versions prior to 63
Firefox ESR versions prior to 60.3
Thunderbird versions prior to 60.3
Description
The issue is related to the implementation of the HTTP Live Streaming protocol in Firefox and Firefox ESR browsers and the Thunderbird email client for Android, which is affected by security setting errors. This allows audio data to be accessed across origins in violation of security policies during HTTP Live Stream playback. The problem is in the underlying Android service.
Recommendations
For Firefox for Android versions prior to 63, update to version 63 or later.
For Firefox ESR versions prior to 60.3, update to version 60.3 or later.
For Thunderbird versions prior to 60.3, update to version 60.3 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Firefox
Firefox Esr
Suse
Thunderbird