MEDIUM · 4.3

CVE-2011-2366

Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate c...

Vulnerability Description

Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.

CVSS Score

4.3

MEDIUM

AV:N/AC:M/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MozillaGecko<= 2
MozillaFirefox<= 4.0.1
MozillaThunderbird<= 3.1.11

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-2366?

CVE-2011-2366 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate c...

How severe is CVE-2011-2366?

CVE-2011-2366 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-2366?

Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Gecko, Mozilla Firefox, Mozilla Thunderbird.