CVE-2010-3813: Medium severity safari vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3813 to the following vulnerability:
Name: CVE-2010-3813 Status: Candidate URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3813 Assigned: 20101007 Reference: CONFIRM:http://support.apple.com/kb/HT4455 Reference: CONFIRM:http://support.apple.com/kb/HT4456
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote attackers to bypass the DNS prefetching setting via an HTML LINK element, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
Upstream: Bugzilla: https://bugs.webkit.org/showbug.cgi?id=42500 Trac: http://trac.webkit.org/changeset/63622
This is fixed in webkitgtk 1.2.6
Other sources
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3813?
CVE-2010-3813 is classified as a candidate vulnerability which may lead to security issues in affected versions of software.
How do I fix CVE-2010-3813?
To address CVE-2010-3813, update affected software packages to their latest secure versions as recommended by the vendor.
Which software is affected by CVE-2010-3813?
CVE-2010-3813 affects various versions of Apple Safari and webkitgtk, particularly those prior to version 1.2.6-2.el6_0 for webkitgtk and 5.0.2 for Safari.
Are there any known exploits for CVE-2010-3813?
No specific exploits for CVE-2010-3813 have been publicly disclosed as of now.
What type of vulnerability is CVE-2010-3813?
CVE-2010-3813 is categorized as a web vulnerability that affects the rendering engine of Safari and webkitgtk.