Red Hat Bugzilla – Bug 977615
CVE-2013-1698 Mozilla: getUserMedia permission dialog incorrectly displays location (MFSA 2013-60)
Last modified: 2013-06-26 02:56:43 EDT
Mozilla engineer Matt Wobensmith discovered that when the getUserMedia permission dialog for an iframe appears in one domain, it will display its origin as that of the top-level document and not the calling framed page. This could lead to users incorrectly giving camera or microphone permissions when confusing the requesting page's location for a hosting one's.
Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges Matt Wobensmith as the original reporter.
This issue does not affect the version of firefox and thunderbird as shipped with Red Hat Enterprise Linux 5 and 6