Mozilla Firefox prior to 34.0, Firefox ESR 31.x prior to 31.3, and Thunderbird prior to 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
mozilla firefox_esr 31.2 |
||
mozilla firefox_esr 31.1.1 |
||
mozilla firefox_esr 31.1.0 |
||
mozilla firefox_esr 31.0 |
||
mozilla thunderbird |
||
mozilla firefox |