CVE-2011-2366
published 2011-06-30CVE-2011-2366: Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.42%
70.2th percentile
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
Affected
208 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mozilla | firefox | <= 4.0.1 | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
| mozilla | firefox | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Firefox regression
vendor_ubuntu·2011-06-23·CVSS 4.3
[MEDIUM] Firefox regression
Title: Firefox regression
Summary: Under certain circumstances, the updated translations could unintentionally
install firefox.
USN-1157-1 fixed vulnerabilities in Firefox. Unfortunately, this update
produced the side effect of pulling in Firefox on some systems that did not
have it installed during a dist-upgrade due to changes in the Ubuntu
language packs. This update fixes the problem. We apologize for the
inconvenience.
Original advisory details:
Bob Clary, Kevin Brosnan, Gary Kwong, Jesse Ruderman, Christian Biesinger,
Bas Schouten, Igor Bukanov, Bill McCloskey, Olli Pettay, Daniel Veditz and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could possibly execute arbitrary code with
the privileges of the user invoking Firefox. (C
Ubuntu
mozvoikko, ubufox, webfav update
vendor_ubuntu·2011-06-22·CVSS 4.3
[MEDIUM] mozvoikko, ubufox, webfav update
Title: mozvoikko, ubufox, webfav update
Summary: This update provides provides packages compatible with Firefox 5.
USN-1157-1 fixed vulnerabilities in Firefox. This update provides updated
packages for use with Firefox 5.
Original advisory details:
Bob Clary, Kevin Brosnan, Gary Kwong, Jesse Ruderman, Christian Biesinger,
Bas Schouten, Igor Bukanov, Bill McCloskey, Olli Pettay, Daniel Veditz and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could possibly execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2011-2374, CVE-2011-2375)
Martin Barbella discovered that under certain conditions, viewing a XUL
document while JavaScript was disabled caused deleted memory to be
accessed. An attacker could potential
Ubuntu
Firefox vulnerabilities
vendor_ubuntu·2011-06-22·CVSS 4.3
CVE-2011-2375 [MEDIUM] Firefox vulnerabilities
Title: Firefox vulnerabilities
Summary: Multiple Firefox vulnerabilities have been fixed
Bob Clary, Kevin Brosnan, Gary Kwong, Jesse Ruderman, Christian Biesinger,
Bas Schouten, Igor Bukanov, Bill McCloskey, Olli Pettay, Daniel Veditz and
Marcia Knous discovered multiple memory vulnerabilities in the browser
rendering engine. An attacker could possibly execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2011-2374, CVE-2011-2375)
Martin Barbella discovered that under certain conditions, viewing a XUL
document while JavaScript was disabled caused deleted memory to be
accessed. An attacker could potentially use this to crash Firefox or
execute arbitrary code with the privileges of the user invoking Firefox.
(CVE-2011-2373)
Jordi Chancel discovered a vulnerability
Red Hat
Mozilla: WebGL cross-domain image theft
vendor_redhat·2011-05-09·CVSS 4.3
CVE-2011-2366 [MEDIUM] Mozilla: WebGL cross-domain image theft
Mozilla: WebGL cross-domain image theft
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
Statement: Not Vulnerable. This issue did not affect the version of Firefox as shipped with Red Hat Enterprise Linux 4, 5 or 6.
Package: firefox (Red Hat Enterprise Linux 4) - Not affected
Package: firefox (Red Hat Enterprise Linux 5) - Not affected
Package: firefox (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-frmv-64q7-356r: Mozilla Gecko before 5
ghsa_unreviewed·2022-05-17
CVE-2011-2366 [MEDIUM] CWE-20 GHSA-frmv-64q7-356r: Mozilla Gecko before 5
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.htmlhttp://lists.whatwg.org/pipermail/whatwg-whatwg.org/2011-March/030882.htmlhttp://www.contextis.co.uk/resources/blog/webgl/http://www.mozilla.org/security/announce/2011/mfsa2011-25.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655987https://bugzilla.mozilla.org/show_bug.cgi?id=656277https://bugzilla.mozilla.org/show_bug.cgi?id=659349https://developer.mozilla.org/en/WebGL/Cross-Domain_Textureshttps://hacks.mozilla.org/2011/06/cross-domain-webgl-textures-disabled-in-firefox-5/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14221http://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.htmlhttp://lists.whatwg.org/pipermail/whatwg-whatwg.org/2011-March/030882.htmlhttp://www.contextis.co.uk/resources/blog/webgl/http://www.mozilla.org/security/announce/2011/mfsa2011-25.htmlhttps://bugzilla.mozilla.org/show_bug.cgi?id=655987https://bugzilla.mozilla.org/show_bug.cgi?id=656277https://bugzilla.mozilla.org/show_bug.cgi?id=659349https://developer.mozilla.org/en/WebGL/Cross-Domain_Textureshttps://hacks.mozilla.org/2011/06/cross-domain-webgl-textures-disabled-in-firefox-5/https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14221
2011-06-30
Published