CVE-2011-2366Improper Input Validation in Mozilla Firefox

Severity
4.3MEDIUMNVD
EPSS
0.6%
top 30.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 30
Latest updateMay 17

Description

Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDmozilla/gecko2+6
NVDmozilla/firefox4.0.1+116
NVDmozilla/thunderbird3.1.11+83

🔴Vulnerability Details

1
GHSA
GHSA-frmv-64q7-356r: Mozilla Gecko before 52022-05-17

📋Vendor Advisories

4
Ubuntu
Firefox regression2011-06-23
Ubuntu
mozvoikko, ubufox, webfav update2011-06-22
Ubuntu
Firefox vulnerabilities2011-06-22
Red Hat
Mozilla: WebGL cross-domain image theft2011-05-09

💬Community

1
Bugzilla
CVE-2011-2366 Mozilla: WebGL cross-domain image theft2011-09-26