CVE-2014-1595: Low severity firefox vulnerability
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-1595?
CVE-2014-1595 is classified as a moderate severity vulnerability that may lead to sensitive information disclosure.
Which products are affected by CVE-2014-1595?
CVE-2014-1595 affects Mozilla Firefox versions prior to 34.0, Firefox ESR versions prior to 31.3, and Mozilla Thunderbird versions prior to 31.3 on macOS.
How do I fix CVE-2014-1595?
To fix CVE-2014-1595, upgrade to the latest version of Mozilla Firefox, Firefox ESR, or Thunderbird that is not vulnerable.
Can local users exploit CVE-2014-1595?
Yes, CVE-2014-1595 can be exploited by local users to read sensitive information from /tmp files.
What platforms are vulnerable to CVE-2014-1595?
CVE-2014-1595 specifically affects applications running on Apple macOS 10.10 and earlier.