Cross-origin policy bypass in Mozilla Firefox - CVE-2018-12391

 

Cross-origin policy bypass in Mozilla Firefox - CVE-2018-12391

Published: October 24, 2018


Vulnerability identifier: #VU15489
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-12391
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restrictions on the target system.

The weakness exists due to audio data can be accessed across origins in violation of security policies during HTTP Live Stream playback on Firefox for Android. A remote attacker can trick the victim into visiting a specially crafted website, bypass cross-origin policies and conduct further attacks.

Affected software

Mozilla Firefox
Firefox ESR
Gentoo Linux
Opensuse
Mozilla Thunderbird

How to mitigate CVE-2018-12391

Update to version 63.0.

Mozilla Firefox - update to 63.0
Mozilla Thunderbird - update to 60.3
Firefox ESR - update to 60.3.0

External References

Related Security Bulletins