CVE-2010-3813
published 2010-11-22CVE-2010-3813: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through…
PriorityP427medium5.8CVSS 2.0
AVNACMAuNCPIPAN
EPSS
1.84%
76.8th percentile
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
Affected
82 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | iphone_os | <= 4.1 | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
| apple | iphone_os | — | — |
CVSS provenance
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
osv5.8MEDIUM
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qv97-4m93-h342: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement
ghsa_unreviewed·2022-05-17
CVE-2010-3813 [MEDIUM] GHSA-qv97-4m93-h342: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
GHSA
GHSA-x3m3-q3xc-8m5j: WebKit in Apple iOS before 4
ghsa_unreviewed·2022-05-17·CVSS 5.8
CVE-2010-3829 [MEDIUM] GHSA-x3m3-q3xc-8m5j: WebKit in Apple iOS before 4
WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality, a related issue to CVE-2010-3813.
OSV
CVE-2010-3829: WebKit in Apple iOS before 4
osv·2010-11-26·CVSS 5.8
CVE-2010-3829 [MEDIUM] CVE-2010-3829: WebKit in Apple iOS before 4
WebKit in Apple iOS before 4.2 allows remote attackers to bypass the remote image loading setting in Mail via an HTML LINK element with a DNS prefetching property, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality, a related issue to CVE-2010-3813.
OSV
CVE-2010-3813: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement
osv·2010-11-22·CVSS 5.8
CVE-2010-3813 [MEDIUM] CVE-2010-3813: The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
Ubuntu
WebKit vulnerabilities
vendor_ubuntu·2011-08-23
CVE-2010-1824 WebKit vulnerabilities
Title: WebKit vulnerabilities
Summary: Multiple security vulnerabilities were fixed in WebKit.
A large number of security issues were discovered in the WebKit browser and
JavaScript engines. If a user were tricked into viewing a malicious
website, a remote attacker could exploit a variety of issues related to web
browser security, including cross-site scripting attacks, denial of
service attacks, and arbitrary code execution.
Instructions: After a standard system update you need to restart any applications that
use WebKit, such as Epiphany and Midori, to make all the necessary changes.
Red Hat
webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
vendor_redhat·2010-11-18·CVSS 5.8
CVE-2010-3813 [MEDIUM] webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
bugzilla·2011-01-04·CVSS 10.0
CVE-2010-4198 [CRITICAL] CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
CVE-2010-4198 CVE-2010-4197 CVE-2010-4204 CVE-2010-4206 CVE-2010-3812 CVE-2010-3813 CVE-2010-4577 CVE-2010-3255 CVE-2010-3119 webkitgtk various flaws [fedora-13]
fedora-13 tracking bug for webkitgtk: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
Adding parent bug CVE-2010-4197
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115
---
Adding parent bug CVE-2010-4206
New bodhi update url:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=656118,656115,656129
---
Adding parent bug CVE-2010-3812
New bodhi update url:
https://admin.fedoraproject.org/up
Bugzilla
CVE-2010-3813 webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
bugzilla·2011-01-04·CVSS 5.8
CVE-2010-3813 [MEDIUM] CVE-2010-3813 webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
CVE-2010-3813 webkit: HTMLLinkElement ignores dnsPrefetchingEnabled setting
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-3813 to
the following vulnerability:
Name: CVE-2010-3813
Status: Candidate
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3813
Assigned: 20101007
Reference: CONFIRM:http://support.apple.com/kb/HT4455
Reference: CONFIRM:http://support.apple.com/kb/HT4456
WebKit in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6
and Windows, and before 4.1.3 on Mac OS X 10.4, allows remote
attackers to bypass the DNS prefetching setting via an HTML LINK
element, as demonstrated by an HTML e-mail message that uses a
LINK element for X-Confirm-Reading-To functionality.
Upstream:
Bugzilla: https://bugs.webkit.org/show_bug.cgi?id=42500
Trac: htt
http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42314http://secunia.com/advisories/43068http://secunia.com/advisories/43086http://support.apple.com/kb/HT4455http://support.apple.com/kb/HT4456http://trac.webkit.org/changeset/63622http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=42500https://bugzilla.redhat.com/show_bug.cgi?id=667024https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12293http://lists.apple.com/archives/security-announce/2010//Nov/msg00002.htmlhttp://lists.apple.com/archives/security-announce/2010//Nov/msg00003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-January/052906.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.htmlhttp://secunia.com/advisories/42314http://secunia.com/advisories/43068http://secunia.com/advisories/43086http://support.apple.com/kb/HT4455http://support.apple.com/kb/HT4456http://trac.webkit.org/changeset/63622http://www.mandriva.com/security/advisories?name=MDVSA-2011:039http://www.redhat.com/support/errata/RHSA-2011-0177.htmlhttp://www.vupen.com/english/advisories/2010/3046http://www.vupen.com/english/advisories/2011/0212http://www.vupen.com/english/advisories/2011/0216http://www.vupen.com/english/advisories/2011/0552https://bugs.webkit.org/show_bug.cgi?id=42500https://bugzilla.redhat.com/show_bug.cgi?id=667024https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12293
2010-11-22
Published