PT-2010-2913 · Mozilla+1 · Firefox+2

Michal Zalewski

·

Publicado

2010-06-25

·

Atualizado

2024-12-12

·

CVE-2010-1206

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Mozilla Firefox versions 3.5.x through 3.5.10 Mozilla Firefox versions 3.6.x through 3.6.6 SeaMonkey versions prior to 2.0.6
Description The issue concerns the implementation of the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading. This allows remote web servers to conduct spoofing attacks via vectors involving a 204 status code, and also enables remote attackers to conduct spoofing attacks via vectors involving a window.stop call.
Recommendations For Mozilla Firefox versions 3.5.x through 3.5.10, update to version 3.5.11 or later. For Mozilla Firefox versions 3.6.x through 3.6.6, update to version 3.6.7 or later. For SeaMonkey versions prior to 2.0.6, update to version 2.0.6 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2010-1206
OPENSUSE-SU-2024:10071-1
OPENSUSE-SU-2024:14572-1
RHSA-2010:0547
RHSA-2010_0547

Produtos afetados

Firefox
Red Hat
Seamonkey