PT-2018-3039 · Mozilla+2 · Firefox Esr+4

Jun Kokatsu

·

Published

2018-06-26

·

Updated

2024-12-12

·

CVE-2018-12391

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Firefox for Android versions prior to 63 Firefox ESR versions prior to 60.3 Thunderbird versions prior to 60.3
Description The issue is related to the implementation of the HTTP Live Streaming protocol in Firefox and Firefox ESR browsers and the Thunderbird email client for Android, which is affected by security setting errors. This allows audio data to be accessed across origins in violation of security policies during HTTP Live Stream playback. The problem is in the underlying Android service.
Recommendations For Firefox for Android versions prior to 63, update to version 63 or later. For Firefox ESR versions prior to 60.3, update to version 60.3 or later. For Thunderbird versions prior to 60.3, update to version 60.3 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2550
ALT-PU-2018-2645
ALT-PU-2018-2669
BDU:2019-03472
CVE-2018-12391
MGASA-2018-0480
OPENSUSE-SU-2018:3687-1
OPENSUSE-SU-2018_3646-1
OPENSUSE-SU-2024:10600-1
OPENSUSE-SU-2024:10601-1
OPENSUSE-SU-2024:14572-1
SUSE-SU-2018:3769-1

Affected Products

Alt Linux
Firefox
Firefox Esr
Suse
Thunderbird