First published: Mon Jul 06 2015(Updated: )
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.
Credit: security@mozilla.org
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Solaris SPARC | =11.3 | |
Mozilla Firefox | <=38.1.0 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2742 has been classified with moderate severity due to the potential exposure of sensitive information.
To fix CVE-2015-2742, update Mozilla Firefox to version 39.0 or later.
CVE-2015-2742 affects all versions of Mozilla Firefox prior to 39.0.
CVE-2015-2742 specifically impacts Mozilla Firefox on OS X.
CVE-2015-2742 can lead to exposure of sensitive key press information through crash-reporting data streams.