CVE-2010-3259: Infoleak
WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3259?
CVE-2010-3259 has a severity rating that indicates a medium risk level due to its potential to bypass security restrictions.
How do I fix CVE-2010-3259?
To fix CVE-2010-3259, you should update affected software to the latest versions provided by the vendors, specifically Google Chrome, Apple Safari, and WebKitGTK+.
Which software is affected by CVE-2010-3259?
CVE-2010-3259 affects Apple Safari versions before 4.1.3 and 5.0.x before 5.0.3, Google Chrome versions before 6.0.472.53, and WebKitGTK+ versions before 1.2.6.
What type of attack is possible with CVE-2010-3259?
CVE-2010-3259 allows remote attackers to bypass the Same Origin Policy, potentially exposing sensitive information from CANVAS elements.
Is CVE-2010-3259 still a threat?
CVE-2010-3259 is primarily a historical threat, but if outdated software is still in use, it could remain vulnerable.