CVE-2014-1595

Publication date 11 December 2014

Last updated 24 July 2024


Ubuntu priority

Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life
thunderbird 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life

Notes


chrisccoulson

Affects OS X 10.10 only