---
title: "CVE-2011-1300\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-1300?format=md
keywords: index, follow
---

# CVE-2011-1300

Publication date 15 April 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in
libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine
(ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the
GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote
attackers to execute arbitrary code via unspecified vectors, related to an
"off-by-three" error.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-1300?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| chromium-browser | 11.10 oneiric | Not affected |
| 11.04 natty | Fixed 14.0.835.202~r103287-0ubuntu0.11.04.1 |
| 10.10 maverick | Fixed 14.0.835.202~r103287-0ubuntu0.10.10.1 |
| 10.04 LTS lucid | Fixed 14.0.835.202~r103287-0ubuntu0.10.04.2 |
| 9.10 karmic | Not in release |
| 8.04 LTS hardy | Not in release |
| 6.06 LTS dapper | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [kees](https://launchpad.net/~kees)

is this strictly Windows-only?

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-1300)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-1300)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-1300)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-1300)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2011-1300>
