Bug 568170 (CVE-2010-0648)

Summary: CVE-2010-0648 webkit: stylesheet URL property leaks redirection target
Product: [Other] Security Response Reporter: Vincent Danen <vdanen>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: jreznik, than
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0648
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2015-08-22 15:08:40 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 589165, 589169    
Bug Blocks:    

Description Vincent Danen 2010-02-24 22:36:19 UTC
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-0648 to
the following vulnerability:

Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.

http://code.google.com/p/chromium/issues/detail?id=32309
http://nomoreroot.blogspot.com/2010/01/little-bug-in-safari-and-google-chrome.html


Note: this issue is supposed to refer to WebKit; I think MITRE got this description wrong as while this issue did affect Mozilla before, they fixed this quite a while ago (CVE-2008-0593, https://bugzilla.mozilla.org/show_bug.cgi?id=397427, MFSA 2008-11), so this really should refer specifically to WebKit.

Comment 2 Tomas Hoger 2010-04-30 14:36:36 UTC
This can be reproduced with webkitgtk 1.1.x, upstream patch is included in 1.2.0.  It's also reproducible with qtwebkit from qt 4.6.2.

Comment 7 Fedora Update System 2010-05-11 06:21:29 UTC
qt-4.6.2-17.fc11 has been submitted as an update for Fedora 11.
http://admin.fedoraproject.org/updates/qt-4.6.2-17.fc11

Comment 8 Fedora Update System 2010-05-11 06:21:33 UTC
qt-4.6.2-17.fc12 has been submitted as an update for Fedora 12.
http://admin.fedoraproject.org/updates/qt-4.6.2-17.fc12

Comment 9 Fedora Update System 2010-05-11 06:22:55 UTC
qt-4.6.2-17.fc13 has been submitted as an update for Fedora 13.
http://admin.fedoraproject.org/updates/qt-4.6.2-17.fc13

Comment 10 Fedora Update System 2010-05-15 20:17:28 UTC
qt-4.6.2-17.fc12 has been pushed to the Fedora 12 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 11 Fedora Update System 2010-05-15 20:33:30 UTC
qt-4.6.2-17.fc11 has been pushed to the Fedora 11 stable repository.  If problems still persist, please make note of it in this bug report.

Comment 12 Fedora Update System 2010-05-15 20:35:06 UTC
qt-4.6.2-17.fc13 has been pushed to the Fedora 13 stable repository.  If problems still persist, please make note of it in this bug report.