CVE-2010-3768: Input Validation
Mozilla added the OTS font sanitizing library to prevent downloadable fonts from exposing vulnerabilities in the underlying OS font code. This library mitigates against several issues independently reported by Red Hat Security Response Team member Marc Schoenefeld and Mozilla security researcher Christoph Diehl.
Other sources
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3768?
The severity of CVE-2010-3768 is classified as medium, indicating a potential risk of font-related attacks.
How do I fix CVE-2010-3768?
To fix CVE-2010-3768, upgrade to the fixed versions of Mozilla Firefox or SeaMonkey as indicated in the security advisory.
What software is affected by CVE-2010-3768?
CVE-2010-3768 affects several versions of Mozilla Firefox 3.6.x and SeaMonkey 1.x software.
What type of vulnerability is CVE-2010-3768?
CVE-2010-3768 is a font processing vulnerability that could lead to potential code execution on the affected systems.
Is there a workaround for CVE-2010-3768?
There are no known effective workarounds for CVE-2010-3768, and updating to secure versions is strongly recommended.