CVE-2010-3774: Input Validation
The NSSecurityCompareURIs function in netwerk/base/public/nsNetUtil.h in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle (1) about:neterror and (2) about:certerror pages, which allows remote attackers to spoof the location bar via a crafted web site.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3774?
CVE-2010-3774 is considered a moderate severity vulnerability.
How do I fix CVE-2010-3774?
To fix CVE-2010-3774, upgrade to Mozilla Firefox version 3.5.16 or later, or 3.6.13 or later, or the respective patched version of SeaMonkey.
What versions of Mozilla Firefox are affected by CVE-2010-3774?
Affected versions of Mozilla Firefox include all 3.6.x versions before 3.6.13 and all 3.5.x versions before 3.5.16.
What is the impact of CVE-2010-3774 on users?
CVE-2010-3774 allows remote attackers to spoof the location bar, which can mislead users into believing they are on a legitimate site.
Is SeaMonkey also affected by CVE-2010-3774?
Yes, SeaMonkey versions before 2.0.11 are affected by CVE-2010-3774.