PT-2011-3949 · Mozilla+2 · Firefox+2
Published
2011-06-30
·
Updated
2011-07-12
·
CVE-2011-2600
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Windows XP
Description
The issue concerns the GPU support functionality in Windows XP, which fails to properly restrict rendering time. This allows remote attackers to cause a system crash via vectors involving WebGL and either shader programs or complex 3D geometry. For example, visiting a specific test page in the Khronos WebGL SDK using browsers like Mozilla Firefox or Google Chrome can demonstrate this issue.
Recommendations
For Windows XP, consider disabling WebGL support in browsers as a temporary workaround until a patch is available. Restrict access to complex 3D geometry and shader programs to minimize the risk of exploitation. Avoid using the
shader programs and 3D geometry features in WebGL-enabled applications until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Firefox
Windows Xp