CVE-2010-3813
Publication date 22 November 2010
Last updated 24 July 2024
Ubuntu priority
The WebCore::HTMLLinkElement::process function in WebCore/html/HTMLLinkElement.cpp in WebKit, as used in Apple Safari before 5.0.3 on Mac OS X 10.5 through 10.6 and Windows, and before 4.1.3 on Mac OS X 10.4; webkitgtk before 1.2.6; and possibly other products does not verify whether DNS prefetching is enabled when processing an HTML LINK element, which allows remote attackers to bypass intended access restrictions, as demonstrated by an HTML e-mail message that uses a LINK element for X-Confirm-Reading-To functionality.
Status
Package | Ubuntu Release | Status |
---|---|---|
qt4-x11 | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
qtwebkit-source | ||
16.04 LTS xenial | Ignored no update available | |
14.04 LTS trusty | Not in release | |
webkit | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
webkitgtk | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty | Not in release | |
Notes
References
Related Ubuntu Security Notices (USN)
- USN-1195-1
- WebKit vulnerabilities
- 23 August 2011