The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.ubuntu.com/usn/USN-1890-1 | vendor advisory |
https://bugzilla.mozilla.org/show_bug.cgi?id=876044 | |
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00005.html | vendor advisory |
http://www.mozilla.org/security/announce/2013/mfsa2013-60.html | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A16791 | vdb entry signature |