FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2010-1767

This CVE name corresponds to:

Entered Topic
2010-07-18 webkit-gtk2 -- Multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2010-1767
Phase Assigned(20100506)

Description

Cross-site request forgery (CSRF) vulnerability in loader/DocumentThreadableLoader.cpp in WebCore in WebKit before r57041, as used in Google Chrome before 4.1.249.1059, allows remote attackers to hijack the authentication of unspecified victims via a crafted synchronous preflight XMLHttpRequest operation.

References

Source Reference
CONFIRM http://code.google.com/p/chromium/issues/detail?id=39698
CONFIRM http://googlechromereleases.blogspot.com/2010/04/stable-update-security-fixes.html
CONFIRM http://security-tracker.debian.org/tracker/CVE-2010-1767
CONFIRM http://trac.webkit.org/changeset/57041
CONFIRM https://bugs.webkit.org/show_bug.cgi?id=36843
MANDRIVA MDVSA-2011:039
SUSE SUSE-SR:2011:002
UBUNTU USN-1006-1
BID 39603
OSVDB 64002
OVAL oval:org.mitre.oval:def:11140
SECUNIA 39544
SECUNIA 41856
SECUNIA 43068
VUPEN ADV-2010-2722
VUPEN ADV-2011-0212
VUPEN ADV-2011-0552