Mozilla Foundation Security Advisory 2016-53

Out-of-bounds write with WebGL shader

Announced
June 7, 2016
Reporter
Aral
Impact
High
Products
Firefox, Firefox ESR
Fixed in
  • Firefox 47
  • Firefox ESR 45.2

Description

Security researcher Aral reported an out-of-bounds write when using the ANGLE graphics library, which is used for WebGL content on Windows systems. This crash occurs due to improper size checking while writing to an array during some WebGL shader operations.

The ANGLE graphics library is only used on Windows. Linux, OS X, and Android operating systems are not affected by this vulnerability.

References