[tor-bugs] #15825 [- Select a component]: webgl.disable-extensions true about:config setting may allow DoS

Tor Bug Tracker & Wiki blackhole at torproject.org
Sun Apr 26 15:41:07 UTC 2015


#15825: webgl.disable-extensions true about:config setting may allow DoS
----------------------------------+---------------------
 Reporter:  cypherpunks           |          Owner:
     Type:  defect                |         Status:  new
 Priority:  normal                |      Milestone:
Component:  - Select a component  |        Version:
 Keywords:                        |  Actual Points:
Parent ID:                        |         Points:
----------------------------------+---------------------
 Reference #3323 and #6370 ...

 "The conclusion is that if we set webgl.min_capability_mode and webgl
 .disable-extensions, our primary API-level fingerprinting concerns are
 addressed."

 However, I am concerned because this presumably disables security
 extensions such as GL_ARB_robustness too, making it easier for malicious
 content to cause crashes on the user's computer (some of which can lead to
 things such as remote code execution).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/15825>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list