PT-2011-3949 · Mozilla+2 · Firefox+2

Publicado

2011-06-30

·

Atualizado

2011-07-12

·

CVE-2011-2600

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Windows XP
Description The issue concerns the GPU support functionality in Windows XP, which fails to properly restrict rendering time. This allows remote attackers to cause a system crash via vectors involving WebGL and either shader programs or complex 3D geometry. For example, visiting a specific test page in the Khronos WebGL SDK using browsers like Mozilla Firefox or Google Chrome can demonstrate this issue.
Recommendations For Windows XP, consider disabling WebGL support in browsers as a temporary workaround until a patch is available. Restrict access to complex 3D geometry and shader programs to minimize the risk of exploitation. Avoid using the shader programs and 3D geometry features in WebGL-enabled applications until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2600

Produtos afetados

Google Chrome
Firefox
Windows Xp