The GPU support functionality in Windows XP does not properly restrict rendering time, which allows remote attackers to cause a denial of service (system crash) via vectors involving WebGL and (1) shader programs or (2) complex 3D geometry, as demonstrated by using Mozilla Firefox or Google Chrome to visit the lots-of-polys-example.html test page in the Khronos WebGL SDK.
References
Link | Resource |
---|---|
http://www.contextis.com/resources/blog/webgl/ | Exploit |
Configurations
Information
Published : 2011-06-30 08:55
Updated : 2011-07-11 21:00
NVD link : CVE-2011-2600
Mitre link : CVE-2011-2600
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
microsoft
- windows_xp