PT-2011-3949 · Mozilla+2 · Firefox+2
Publicado
2011-06-30
·
Atualizado
2011-07-12
·
CVE-2011-2600
CVSS v2.0
7.1
Alta
| Vetor | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Windows XP
Description
The issue concerns the GPU support functionality in Windows XP, which fails to properly restrict rendering time. This allows remote attackers to cause a system crash via vectors involving WebGL and either shader programs or complex 3D geometry. For example, visiting a specific test page in the Khronos WebGL SDK using browsers like Mozilla Firefox or Google Chrome can demonstrate this issue.
Recommendations
For Windows XP, consider disabling WebGL support in browsers as a temporary workaround until a patch is available. Restrict access to complex 3D geometry and shader programs to minimize the risk of exploitation. Avoid using the
shader programs and 3D geometry features in WebGL-enabled applications until the issue is resolved.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Chrome
Firefox
Windows Xp