CVE-2011-2600

The GPU support functionality in Windows XP does not properly restrict rendering time, which allows remote attackers to cause a denial of service (system crash) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.
Configurations

Configuration 1 (hide)

cpe:2.3:o:microsoft:windows_xp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:28

Type Values Removed Values Added
References () http://www.contextis.com/resources/blog/webgl/ - Exploit () http://www.contextis.com/resources/blog/webgl/ - Exploit

Information

Published : 2011-06-30 15:55

Updated : 2024-11-21 01:28


NVD link : CVE-2011-2600

Mitre link : CVE-2011-2600

CVE.ORG link : CVE-2011-2600


JSON object : View

Products Affected

microsoft

  • windows_xp
CWE
CWE-264

Permissions, Privileges, and Access Controls