CVE-2010-1207: Medium severity firefox vulnerability
Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1207?
CVE-2010-1207 has been classified as a medium-severity vulnerability due to the potential for cross-origin information leakage.
How do I fix CVE-2010-1207?
To fix CVE-2010-1207, upgrade to Mozilla Firefox 3.6.7 or later, or Thunderbird 3.1.1 or later.
Which versions of Firefox are affected by CVE-2010-1207?
CVE-2010-1207 affects Firefox versions prior to 3.6.7 including 3.6.2 through 3.6.6.
Which versions of Thunderbird are affected by CVE-2010-1207?
CVE-2010-1207 affects all versions of Thunderbird prior to 3.1.1.
What type of attack does CVE-2010-1207 enable?
CVE-2010-1207 enables remote attackers to obtain sensitive information from other origins through insufficient read restrictions on CANVAS elements.