Vulnerability CVE-2018-12391: Information

Description

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Published: Feb. 28, 2019
Modified: Aug. 24, 2020
Error type identifier: CWE-863

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
firefoxsisyphus63.0.1-alt1125.0.2-alt1ALT-PU-2018-2645-1216395Fixed
firefoxp1063.0.1-alt1118.0.2-alt0.p10.1ALT-PU-2018-2645-1216395Fixed
firefoxp963.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2018-2645-1216395Fixed
firefoxp863.0.3-alt0.M80P.168.0.1-alt0.M80P.1ALT-PU-2018-2742-1216526Fixed
firefoxc10f163.0.1-alt1112.0.2-alt0.p10.1ALT-PU-2018-2645-1216395Fixed
firefoxc9f263.0.1-alt1105.0.1-alt0.c9.1ALT-PU-2018-2645-1216395Fixed
firefoxc760.6.1-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-1726-1218597Fixed
firefox-esrsisyphus60.3.0-alt1115.10.0-alt1ALT-PU-2018-2550-1215469Fixed
firefox-esrp1060.3.0-alt1115.10.0-alt1ALT-PU-2018-2550-1215469Fixed
firefox-esrp960.3.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-2550-1215469Fixed
firefox-esrp860.3.0-alt0.M80P.168.4.1-alt0.M80P.1ALT-PU-2018-2565-1215471Fixed
firefox-esrc10f160.3.0-alt1115.9.1-alt0.c10.1ALT-PU-2018-2550-1215469Fixed
firefox-esrc9f260.3.0-alt1102.12.0-alt0.c9.1ALT-PU-2018-2550-1215469Fixed
thunderbirdsisyphus60.3.0-alt1115.9.0-alt1ALT-PU-2018-2669-1210777Fixed
thunderbirdp1060.3.0-alt1115.9.0-alt1ALT-PU-2018-2669-1210777Fixed
thunderbirdp960.3.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-2669-1210777Fixed
thunderbirdp860.7.2-alt0.M80P.160.8.0-alt0.M80P.1ALT-PU-2019-2196-1216874Fixed
thunderbirdc10f160.3.0-alt1115.9.0-alt0.c10.1ALT-PU-2018-2669-1210777Fixed
thunderbirdc9f260.3.0-alt1102.11.0-alt0.c9.1ALT-PU-2018-2669-1210777Fixed
thunderbirdc760.8.0-alt0.M70C.160.8.0-alt0.M70C.1ALT-PU-2019-2345-1234994Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://www.mozilla.org/security/advisories/mfsa2018-28/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-27/
  • Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2018-26/
  • Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1478843
  • Issue Tracking
  • Permissions Required
  • Vendor Advisory
GLSA-201811-13
  • Third Party Advisory
1041944
  • Third Party Advisory
  • VDB Entry
105769
  • Third Party Advisory
  • VDB Entry
105718
  • Third Party Advisory
  • VDB Entry
    1. Configuration 1

      cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*

      cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*

      cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:o:google:android:-:*:*:*:*:*:*:*