FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-1206

This CVE name corresponds to:

Entered Topic
2010-07-21 mozilla -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-1206
Phase Assigned(20100330)

Description

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

References

Source Reference
MISC http://lcamtuf.blogspot.com/2010/06/yeah-about-that-address-bar-thing.html
CONFIRM http://hg.mozilla.org/mozilla-central/rev/cadddabb1178
CONFIRM https://bugzilla.mozilla.org/show_bug.cgi?id=556957
CONFIRM http://www.mozilla.org/security/announce/2010/mfsa2010-45.html
OVAL oval:org.mitre.oval:def:8248
SECUNIA 40283