CVE-2018-12391
Summary
| CVE | CVE-2018-12391 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-28 18:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| 1478843 - (CVE-2018-12391) Cross-origin audio leak in HLS |
CONFIRM |
bugzilla.mozilla.org |
Issue Tracking, Permissions Required, Vendor Advisory |
| RETIRED: Mozilla Thunderbird MFSA2018-28 Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Firefox ESR 60.3 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Firefox and Firefox ESR Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Mozilla Firefox Multiple Bugs Let Remote Users Deny Service, Obtain Potentially Sensitive Information, and Execute Arbitrary Code - SecurityTracker |
SECTRACK |
www.securitytracker.com |
Third Party Advisory, VDB Entry |
| Security vulnerabilities fixed in Firefox 63 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Security vulnerabilities fixed in Thunderbird ESR 60.3 — Mozilla |
CONFIRM |
www.mozilla.org |
Vendor Advisory |
| Mozilla Thunderbird: Multiple vulnerabilities (GLSA 201811-13) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710285 Gentoo Linux Mozilla Thunderbird Multiple Vulnerabilities (GLSA 201811-13)