Profile path leaks to Android system log

Related Vulnerabilities: CVE-2014-1484  

Mozilla Foundation Security Advisory 2014-06

Profile path leaks to Android system log

Announced
February 4, 2014
Reporter
Roee Hay
Impact
Moderate
Products
Firefox
Fixed in
  • Firefox 27

Description

Mozilla developer Roee Hay reported that Firefox for Android profile paths leak to the Android system log. When running on Android 4.2 or earlier, other applications are able to read these log files, leading to information disclosure from the user's profile directory. This issue was also independently reported by Mozilla developer Richard Newman.

References