Description
Mozilla Gecko before 5.0, as used in Firefox before 5.0 and Thunderbird before 5.0, does not block use of a cross-domain image as a WebGL texture, which allows remote attackers to obtain approximate copies of arbitrary images via a timing attack involving a crafted WebGL fragment shader.
Affected products
- Mozilla / Firefox1.5.6 – 1.5.6
- Mozilla / Firefox1.5.0.9 – 1.5.0.9
- Mozilla / Firefox1.5.0.10 – 1.5.0.10
- Mozilla / Firefox1.5.0.11 – 1.5.0.11
- Mozilla / Firefox1.5.0.12 – 1.5.0.12
- Mozilla / Firefox1.5.1 – 1.5.1
- Mozilla / Firefox1.5.2 – 1.5.2
- Mozilla / Firefox1.5.3 – 1.5.3
- Mozilla / Firefox1.5.4 – 1.5.4
- Mozilla / Firefox1.5.5 – 1.5.5
- Mozilla / Firefox1.5.7 – 1.5.7
- Mozilla / Firefox1.5.8 – 1.5.8
- Mozilla / Firefox1.8 – 1.8
- Mozilla / Firefox2.0 – 2.0
- Mozilla / Firefox2.0.0.1 – 2.0.0.1
- Mozilla / Firefox2.0.0.2 – 2.0.0.2
- Mozilla / Firefox2.0.0.3 – 2.0.0.3
- Mozilla / Firefox2.0.0.4 – 2.0.0.4
- Mozilla / Firefox2.0.0.5 – 2.0.0.5
- Mozilla / Firefox2.0.0.6 – 2.0.0.6
- Mozilla / Firefox2.0.0.7 – 2.0.0.7
- Mozilla / Firefox2.0.0.8 – 2.0.0.8
- Mozilla / Firefox2.0.0.9 – 2.0.0.9
- Mozilla / Firefox2.0.0.10 – 2.0.0.10
- Mozilla / Firefox2.0.0.11 – 2.0.0.11
- Mozilla / Firefox2.0.0.12 – 2.0.0.12
- Mozilla / Firefox2.0.0.13 – 2.0.0.13
- Mozilla / Firefox2.0.0.14 – 2.0.0.14
- Mozilla / Firefox2.0.0.15 – 2.0.0.15
- Mozilla / Firefox2.0.0.16 – 2.0.0.16
- Mozilla / Firefox2.0.0.17 – 2.0.0.17
- Mozilla / Firefox2.0.0.18 – 2.0.0.18
- Mozilla / Firefox2.0.0.19 – 2.0.0.19
- Mozilla / Firefox2.0.0.20 – 2.0.0.20
- Mozilla / Firefox3.0 – 3.0
- Mozilla / Firefox3.0.1 – 3.0.1
- Mozilla / Firefox3.0.2 – 3.0.2
- Mozilla / Firefox3.0.3 – 3.0.3
- Mozilla / Firefox3.0.4 – 3.0.4
- Mozilla / Firefox3.0.5 – 3.0.5
- Mozilla / Firefox3.0.6 – 3.0.6
- Mozilla / Firefox3.0.7 – 3.0.7
- Mozilla / Firefox3.0.8 – 3.0.8
- Mozilla / Firefox3.0.9 – 3.0.9
- Mozilla / Firefox3.0.10 – 3.0.10
- Mozilla / Firefox3.0.11 – 3.0.11
- Mozilla / Firefox3.0.12 – 3.0.12
- Mozilla / Firefox3.0.13 – 3.0.13
- Mozilla / Firefox3.0.14 – 3.0.14
- Mozilla / Firefox3.0.15 – 3.0.15
- Mozilla / Firefox3.0.16 – 3.0.16
- Mozilla / Firefox3.0.17 – 3.0.17
- Mozilla / Firefox3.5 – 3.5
- Mozilla / Firefox3.5.1 – 3.5.1
- Mozilla / Firefox3.5.2 – 3.5.2
- Mozilla / Firefox3.5.3 – 3.5.3
- Mozilla / Firefox3.5.4 – 3.5.4
- Mozilla / Firefox3.5.5 – 3.5.5
- Mozilla / Firefox3.5.6 – 3.5.6
- Mozilla / Firefox3.5.7 – 3.5.7
- Mozilla / Firefox3.5.8 – 3.5.8
- Mozilla / Firefox3.5.9 – 3.5.9
- Mozilla / Firefox3.5.10 – 3.5.10
- Mozilla / Firefox3.5.11 – 3.5.11
- Mozilla / Firefox3.5.12 – 3.5.12
- Mozilla / Firefox3.5.13 – 3.5.13
- Mozilla / Firefox3.5.14 – 3.5.14
- Mozilla / Firefox3.5.15 – 3.5.15
- Mozilla / Firefox3.6 – 3.6
- Mozilla / Firefox3.6.2 – 3.6.2
- Mozilla / Firefox3.6.3 – 3.6.3
- Mozilla / Firefox3.6.4 – 3.6.4
- Mozilla / Firefox3.6.6 – 3.6.6
- Mozilla / Firefox3.6.7 – 3.6.7
- Mozilla / Firefox3.6.8 – 3.6.8
- Mozilla / Firefox3.6.9 – 3.6.9
- Mozilla / Firefox3.6.10 – 3.6.10
- Mozilla / Firefox3.6.11 – 3.6.11
- Mozilla / Firefox3.6.12 – 3.6.12
- Mozilla / Firefox3.6.13 – 3.6.13
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0 – 4.0
- Mozilla / Firefox4.0.1
- Mozilla / Firefox0.1 – 0.1
- Mozilla / Firefox0.2 – 0.2
- Mozilla / Firefox0.3 – 0.3
- Mozilla / Firefox0.4 – 0.4
- Mozilla / Firefox0.5 – 0.5
- Mozilla / Firefox0.6 – 0.6
- Mozilla / Firefox0.6.1 – 0.6.1
- Mozilla / Firefox0.7 – 0.7
- Mozilla / Firefox0.7.1 – 0.7.1
- Mozilla / Firefox0.8 – 0.8
- Mozilla / Firefox0.9 – 0.9
- Mozilla / Firefox0.9 – 0.9
- Mozilla / Firefox0.9.1 – 0.9.1
- Mozilla / Firefox0.9.2 – 0.9.2
- Mozilla / Firefox0.9.3 – 0.9.3
- Mozilla / Firefox0.10 – 0.10
- Mozilla / Firefox0.10.1 – 0.10.1
- Mozilla / Firefox1.0 – 1.0
- Mozilla / Firefox1.0 – 1.0
- Mozilla / Firefox1.0.1 – 1.0.1
- Mozilla / Firefox1.0.2 – 1.0.2
- Mozilla / Firefox1.0.3 – 1.0.3
- Mozilla / Firefox1.0.4 – 1.0.4
- Mozilla / Firefox1.0.5 – 1.0.5
- Mozilla / Firefox1.0.6 – 1.0.6
- Mozilla / Firefox1.0.7 – 1.0.7
- Mozilla / Firefox1.0.8 – 1.0.8
- Mozilla / Firefox1.4.1 – 1.4.1
- Mozilla / Firefox1.5 – 1.5
- Mozilla / Firefox1.5 – 1.5
- Mozilla / Firefox1.5 – 1.5
- Mozilla / Firefox1.5.0.1 – 1.5.0.1
- Mozilla / Firefox1.5.0.2 – 1.5.0.2
- Mozilla / Firefox1.5.0.3 – 1.5.0.3
- Mozilla / Firefox1.5.0.4 – 1.5.0.4
- Mozilla / Firefox1.5.0.5 – 1.5.0.5
- Mozilla / Firefox1.5.0.6 – 1.5.0.6
- Mozilla / Firefox1.5.0.7 – 1.5.0.7
- Mozilla / Firefox1.5.0.8 – 1.5.0.8
- Mozilla / gecko2
- Mozilla / gecko1.9.2 – 1.9.2
- Mozilla / gecko1.8 – 1.8
- Mozilla / gecko1.8.1 – 1.8.1
- Mozilla / gecko1.9 – 1.9
- Mozilla / gecko1.9.1 – 1.9.1
- Mozilla / gecko1.7 – 1.7
- Mozilla / Thunderbird2.0.0.1 – 2.0.0.1
- Mozilla / Thunderbird2.0.0.2 – 2.0.0.2
- Mozilla / Thunderbird2.0.0.3 – 2.0.0.3
- Mozilla / Thunderbird2.0.0.4 – 2.0.0.4
- Mozilla / Thunderbird2.0.0.5 – 2.0.0.5
- Mozilla / Thunderbird2.0.0.6 – 2.0.0.6
- Mozilla / Thunderbird2.0.0.7 – 2.0.0.7
- Mozilla / Thunderbird2.0.0.8 – 2.0.0.8
- Mozilla / Thunderbird2.0.0.9 – 2.0.0.9
- Mozilla / Thunderbird2.0.0.12 – 2.0.0.12
- Mozilla / Thunderbird2.0.0.14 – 2.0.0.14
- Mozilla / Thunderbird2.0.0.16 – 2.0.0.16
- Mozilla / Thunderbird2.0.0.17 – 2.0.0.17
- Mozilla / Thunderbird2.0.0.18 – 2.0.0.18
- Mozilla / Thunderbird2.0.0.19 – 2.0.0.19
- Mozilla / Thunderbird2.0.0.21 – 2.0.0.21
- Mozilla / Thunderbird2.0.0.22 – 2.0.0.22
- Mozilla / Thunderbird2.0.0.23 – 2.0.0.23
- Mozilla / Thunderbird3.0 – 3.0
- Mozilla / Thunderbird3.0.1 – 3.0.1
- Mozilla / Thunderbird3.0.2 – 3.0.2
- Mozilla / Thunderbird3.0.3 – 3.0.3
- Mozilla / Thunderbird3.0.4 – 3.0.4
- Mozilla / Thunderbird3.0.5 – 3.0.5
- Mozilla / Thunderbird3.0.6 – 3.0.6
- Mozilla / Thunderbird3.0.7 – 3.0.7
- Mozilla / Thunderbird3.0.8 – 3.0.8
- Mozilla / Thunderbird3.0.9 – 3.0.9
- Mozilla / Thunderbird3.0.10 – 3.0.10
- Mozilla / Thunderbird3.0.11 – 3.0.11
- Mozilla / Thunderbird3.1 – 3.1
- Mozilla / Thunderbird3.1.1 – 3.1.1
- Mozilla / Thunderbird3.1.2 – 3.1.2
- Mozilla / Thunderbird3.1.3 – 3.1.3
- Mozilla / Thunderbird3.1.4 – 3.1.4
- Mozilla / Thunderbird3.1.5 – 3.1.5
- Mozilla / Thunderbird3.1.6 – 3.1.6
- Mozilla / Thunderbird3.1.7 – 3.1.7
- Mozilla / Thunderbird3.1.8 – 3.1.8
- Mozilla / Thunderbird3.1.9 – 3.1.9
- Mozilla / Thunderbird3.1.10 – 3.1.10
- Mozilla / Thunderbird3.1.11
- Mozilla / Thunderbird0.1 – 0.1
- Mozilla / Thunderbird0.2 – 0.2
- Mozilla / Thunderbird0.3 – 0.3
- Mozilla / Thunderbird0.4 – 0.4
- Mozilla / Thunderbird0.5 – 0.5
- Mozilla / Thunderbird0.6 – 0.6
- Mozilla / Thunderbird0.7 – 0.7
- Mozilla / Thunderbird0.7.1 – 0.7.1
- Mozilla / Thunderbird0.7.2 – 0.7.2
- Mozilla / Thunderbird0.7.3 – 0.7.3
- Mozilla / Thunderbird0.8 – 0.8
- Mozilla / Thunderbird0.9 – 0.9
- Mozilla / Thunderbird1.0 – 1.0
- Mozilla / Thunderbird1.0.1 – 1.0.1
- Mozilla / Thunderbird1.0.2 – 1.0.2
- Mozilla / Thunderbird1.0.3 – 1.0.3
- Mozilla / Thunderbird1.0.4 – 1.0.4
- Mozilla / Thunderbird1.0.5 – 1.0.5
- Mozilla / Thunderbird1.0.6 – 1.0.6
- Mozilla / Thunderbird1.0.7 – 1.0.7
- Mozilla / Thunderbird1.0.8 – 1.0.8
- Mozilla / Thunderbird1.5 – 1.5
- Mozilla / Thunderbird1.5 – 1.5
- Mozilla / Thunderbird1.5.0.1 – 1.5.0.1
- Mozilla / Thunderbird1.5.0.2 – 1.5.0.2
- Mozilla / Thunderbird1.5.0.3 – 1.5.0.3
- Mozilla / Thunderbird1.5.0.4 – 1.5.0.4
- Mozilla / Thunderbird1.5.0.5 – 1.5.0.5
- Mozilla / Thunderbird1.5.0.6 – 1.5.0.6
- Mozilla / Thunderbird1.5.0.7 – 1.5.0.7
- Mozilla / Thunderbird1.5.0.8 – 1.5.0.8
- Mozilla / Thunderbird1.5.0.9 – 1.5.0.9
- Mozilla / Thunderbird1.5.0.10 – 1.5.0.10
- Mozilla / Thunderbird1.5.0.11 – 1.5.0.11
- Mozilla / Thunderbird1.5.0.12 – 1.5.0.12
- Mozilla / Thunderbird1.5.0.13 – 1.5.0.13
- Mozilla / Thunderbird1.5.0.14 – 1.5.0.14
- Mozilla / Thunderbird1.5.1 – 1.5.1
- Mozilla / Thunderbird1.5.2 – 1.5.2
- Mozilla / Thunderbird1.7.1 – 1.7.1
- Mozilla / Thunderbird1.7.3 – 1.7.3
- Mozilla / Thunderbird2.0 – 2.0
- Mozilla / Thunderbird2.0.0.0 – 2.0.0.0
References
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=655987
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14221
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=659349
- MISChttps://hacks.mozilla.org/2011/06/cross-domain-webgl-textures-disabled-in-firefox-5/
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2011-07/msg00001.html
- MISChttp://www.contextis.co.uk/resources/blog/webgl/
- MISChttps://developer.mozilla.org/en/WebGL/Cross-Domain_Textures
- MISChttps://bugzilla.mozilla.org/show_bug.cgi?id=656277
- MAILING_LISThttp://lists.whatwg.org/pipermail/whatwg-whatwg.org/2011-March/030882.html
- MISChttp://www.mozilla.org/security/announce/2011/mfsa2011-25.html