Red Hat Bugzilla – Bug 630074
CVE-2010-2768 Mozilla UTF-7 XSS by overriding document charset using <object> type attribute (MFSA 2010-61)
Last modified: 2016-03-04 07:23:12 EST
Security researchers David Lin-Shung Huang and Collin Jackson of Carnegie Mellon University CyLab reported that the type attribute of an <object> tag can override the charset of a framed HTML document, even when the document is included across origins. A page could be constructed containing such an <object> tag which sets the charset of the framed document to UTF-7. This could potentially allow an attacker to inject UTF-7 encoded JavaScript into a site, bypassing the site's XSS filters, and then executing the code using the above technique.
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-61.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Via RHSA-2010:0682 https://rhn.redhat.com/errata/RHSA-2010-0682.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Via RHSA-2010:0681 https://rhn.redhat.com/errata/RHSA-2010-0681.html
This issue has been addressed in following products: Red Hat Enterprise Linux 3 Red Hat Enterprise Linux 4 Via RHSA-2010:0680 https://rhn.redhat.com/errata/RHSA-2010-0680.html