During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade linux-seamonkeyUpgrade linux-thunderbirdUpgrade thunderbirdUpgrade linux-firefoxUpgrade firefox-esrUpgrade seamonkeyUpgrade waterfoxUpgrade firefoxUpgrade libxul | Oct 24, 2018 | Oct 23, 2018 |
| Gentoo Linux | — | Upgrade mail-client/thunderbird-bin.Upgrade mail-client/thunderbird. | Nov 26, 2018 | Nov 24, 2018 |
| Oracle Solaris | — | Upgrade mail/thunderbird to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade mail/thunderbird/plugin/thunderbird-lightning to version 60.6.1-11.4.9.0.1.2.0 on Solaris 11.4Upgrade web/browser/firefox to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4Upgrade web/data/firefox-bookmarks to version 60.5.0-11.4.6.0.1.4.0 on Solaris 11.4 | Feb 20, 2019 | Feb 20, 2019 |
| Suse | — | Upgrade MozillaThunderbirdUpgrade MozillaThunderbird-translations-otherUpgrade MozillaThunderbird-buildsymbolsUpgrade MozillaThunderbird-translations-common | Nov 8, 2018 | Oct 23, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub