CVE-2011-2601

The GPU support functionality in Mac OS X does not properly restrict rendering time, which allows remote attackers to cause a denial of service (desktop hang) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.
Configurations

Configuration 1 (hide)

cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:*

History

21 Nov 2024, 01:28

Type Values Removed Values Added
References () http://www.contextis.com/resources/blog/webgl/ - Exploit () http://www.contextis.com/resources/blog/webgl/ - Exploit

Information

Published : 2011-06-30 15:55

Updated : 2024-11-21 01:28


NVD link : CVE-2011-2601

Mitre link : CVE-2011-2601

CVE.ORG link : CVE-2011-2601


JSON object : View

Products Affected

apple

  • mac_os_x
CWE
CWE-264

Permissions, Privileges, and Access Controls