Back to search
CVE-2014-1595
Published: Dec 11, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.mozilla.org/show_bug.cgi?id=1092855
x_refsource_CONFIRM
http://www.mozilla.org/security/announce/2014/mfsa2014-90.html
x_refsource_CONFIRM
http://support.apple.com/HT204244
x_refsource_CONFIRM
APPLE-SA-2015-01-27-4
vendor-advisory
x_refsource_APPLE
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now