CVE Vulnerabilities

CVE-2014-1595

Published: Dec 11, 2014 | Modified: Oct 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.

Affected Software

Name Vendor Start Version End Version
Firefox Mozilla 31.0 (including) 31.0 (including)
Firefox Mozilla 31.1.0 (including) 31.1.0 (including)
Firefox Mozilla 31.1.1 (including) 31.1.1 (including)
Firefox_esr Mozilla 31.2 (including) 31.2 (including)
Firefox Ubuntu lucid *
Firefox Ubuntu upstream *
Thunderbird Ubuntu lucid *
Thunderbird Ubuntu upstream *

References