Vulnerability Description
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mozilla | Firefox | 31.0 |
| Mozilla | Firefox Esr | 31.2 |
| Apple | Mac Os X | 10.10.0 |
| Mozilla | Thunderbird | <= 31.2 |
Related Weaknesses (CWE)
References
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
- http://support.apple.com/HT204244
- http://www.mozilla.org/security/announce/2014/mfsa2014-90.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.reddit.com/r/netsec/comments/2ocxac/apple_coregraphics_framework_on_o
- https://bugzilla.mozilla.org/show_bug.cgi?id=1092855
- http://lists.apple.com/archives/security-announce/2015/Jan/msg00003.html
- http://support.apple.com/HT204244
- http://www.mozilla.org/security/announce/2014/mfsa2014-90.htmlVendor Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
- http://www.reddit.com/r/netsec/comments/2ocxac/apple_coregraphics_framework_on_o
- https://bugzilla.mozilla.org/show_bug.cgi?id=1092855
FAQ
What is CVE-2014-1595?
CVE-2014-1595 is a vulnerability with a CVSS score of 2.1 (LOW). Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, whi...
How severe is CVE-2014-1595?
CVE-2014-1595 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1595?
Check the references section above for vendor advisories and patch information. Affected products include: Mozilla Firefox, Mozilla Firefox Esr, Apple Mac Os X, Mozilla Thunderbird.