FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-1698

This CVE name corresponds to:

Entered Topic
2013-06-26 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-1698
Phase Assigned(20130213)

Description

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

References

Source Reference
CONFIRM http://www.mozilla.org/security/announce/2013/mfsa2013-60.html
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=876044
SUSE openSUSE-SU-2013:1142
UBUNTU USN-1890-1
OVAL oval:org.mitre.oval:def:16791