CVE-2010-1585: Input Validation
The nsIScriptableUnescapeHTML.parseFragment method in the ParanoidFragmentSink protection mechanism in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 does not properly sanitize HTML in a chrome document, which makes it easier for remote attackers to execute arbitrary JavaScript with chrome privileges via a javascript: URI in input to an extension, as demonstrated by a javascript:alert sequence in (1) the HREF attribute of an A element or (2) the ACTION attribute of a FORM element.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-1585?
CVE-2010-1585 has a moderate severity rating as it can lead to cross-context scripting attacks.
How do I fix CVE-2010-1585?
To fix CVE-2010-1585, users should upgrade to the latest versions of Mozilla Firefox, Thunderbird, or SeaMonkey that are not affected by this vulnerability.
What versions are affected by CVE-2010-1585?
CVE-2010-1585 affects Mozilla Firefox versions before 3.6.14, Thunderbird versions before 3.1.8, and SeaMonkey versions before 2.0.12.
What kind of attack does CVE-2010-1585 allow?
CVE-2010-1585 allows attackers to execute malicious scripts via improperly sanitized HTML in Chrome documents.
Is there a workaround for CVE-2010-1585 if I cannot update?
There are no specific workarounds for CVE-2010-1585; the best practice is to update to a patched version of the software.