Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux_enterprise_desktop | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_server | Suse | 11-sp3 (including) | 11-sp3 (including) |
Linux_enterprise_software_development_kit | Suse | 11-sp3 (including) | 11-sp3 (including) |
Firefox | Ubuntu | devel | * |
Firefox | Ubuntu | lucid | * |
Firefox | Ubuntu | precise | * |
Firefox | Ubuntu | quantal | * |
Firefox | Ubuntu | saucy | * |
Firefox | Ubuntu | upstream | * |