Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple OS X 10.10 omit a CoreGraphics disable-logging action that is needed by jemalloc-based applications, which allows local users to obtain sensitive information by reading /tmp files, as demonstrated by credential information.
2014-12-11T11:59:09.243
2025-04-12T10:46:40.837
Deferred
CVSSv2: 2.1 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mozilla | firefox | 31.0 | Yes |
| Application | mozilla | firefox | 31.1.0 | Yes |
| Application | mozilla | firefox | 31.1.1 | Yes |
| Application | mozilla | firefox_esr | 31.2 | Yes |
| Operating System | apple | mac_os_x | 10.10.0 | No |
| Application | mozilla | thunderbird | ≤ 31.2 | Yes |
| Operating System | apple | mac_os_x | 10.10.0 | No |
| Application | mozilla | firefox | ≤ 33.0 | Yes |
| Operating System | apple | mac_os_x | 10.10.0 | No |