CVE-2018-4278

MEDIUM

Description

In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, sound fetched through audio elements may be exfiltrated cross-origin. This issue was addressed with improved audio taint tracking.

References

http://www.securitytracker.com/id/1041232

https://exchange.xforce.ibmcloud.com/vulnerabilities/146479

https://security.gentoo.org/glsa/201808-04

https://support.apple.com/HT208932

https://support.apple.com/HT208933,

https://support.apple.com/HT208934,

https://support.apple.com/HT208936,

https://support.apple.com/HT208938,

https://usn.ubuntu.com/3743-1/

Details

Source: MITRE

Published: 2019-01-11

Updated: 2019-03-08

Type: CWE-254

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 4.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Impact Score: 1.4

Exploitability Score: 2.8

Severity: MEDIUM