First published: Thu Dec 11 2014(Updated: )
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
Credit: security@mozilla.org security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Mozilla Firefox | =31.0 | |
Mozilla Firefox | =31.1.0 | |
Mozilla Firefox | =31.1.1 | |
Mozilla Firefox ESR | =31.2 | |
macOS Yosemite | =10.10.0 | |
All of | ||
Mozilla Thunderbird | <=31.2 | |
macOS Yosemite | =10.10.0 | |
All of | ||
Mozilla Firefox | <=33.0 | |
macOS Yosemite | =10.10.0 | |
Mozilla Firefox ESR | =31.0 | |
Mozilla Firefox ESR | =31.1.0 | |
Mozilla Firefox ESR | =31.1.1 | |
Mozilla Firefox ESR | =31.2 | |
macOS Yosemite | =10.10.0 | |
Mozilla Thunderbird | <=31.2 | |
Mozilla Firefox | <=33.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-1595 is classified as a moderate severity vulnerability that may lead to sensitive information disclosure.
CVE-2014-1595 affects Mozilla Firefox versions prior to 34.0, Firefox ESR versions prior to 31.3, and Mozilla Thunderbird versions prior to 31.3 on macOS.
To fix CVE-2014-1595, upgrade to the latest version of Mozilla Firefox, Firefox ESR, or Thunderbird that is not vulnerable.
Yes, CVE-2014-1595 can be exploited by local users to read sensitive information from /tmp files.
CVE-2014-1595 specifically affects applications running on Apple macOS 10.10 and earlier.