CVE-2010-0648: Infoleak
Mozilla Firefox, possibly before 3.6, allows remote attackers to discover a redirect's target URL, for the session of a specific user of a web site, by placing the site's URL in the HREF attribute of a stylesheet LINK element, and then reading the document.styleSheets[0].href property value, related to an IFRAME element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0648?
CVE-2010-0648 has a moderate severity rating as it allows remote attackers to discover redirect targets.
How do I fix CVE-2010-0648?
To fix CVE-2010-0648, users should update their Firefox browser to a version that includes the security patch.
Which versions of Firefox are affected by CVE-2010-0648?
CVE-2010-0648 affects multiple versions of Firefox prior to 3.6, including 1.0 to 3.5.7.
What are the potential impacts of CVE-2010-0648?
The potential impact of CVE-2010-0648 includes exposure of sensitive information through redirect links.
Is there a workaround for CVE-2010-0648?
There is no specific workaround for CVE-2010-0648; updating to a patched version is the recommended solution.