Red Hat Bugzilla – Bug 660438
CVE-2010-3774 Mozilla location bar SSL spoofing using network error page (MFSA 2010-83)
Last modified: 2013-04-12 14:51:36 EDT
Google security researcher Michal Zalewski reported that when a window was opened to a site resulting in a network or certificate error page, the opening site could access the document inside the opened window and inject arbitrary content. An attacker could use this bug to spoof the location bar and trick a user into thinking they were on a different site than they actually were.
This is now public: http://www.mozilla.org/security/announce/2010/mfsa2010-83.html
This issue has been addressed in following products: Red Hat Enterprise Linux 4 Red Hat Enterprise Linux 5 Red Hat Enterprise Linux 6 Via RHSA-2010:0966 https://rhn.redhat.com/errata/RHSA-2010-0966.html