Apple CoreGraphics framework on OS X 10.10 logging input data to /tmp directory — Mozilla

Mozilla Menu Mission About Products Get Involved Home > Mozilla Security > Security Advisories > Announced December 2, 2014 Reporter Kent Howard Impact High Products Firefox, Firefox ESR, Thunderbird Fixed in Firefox 34 Firefox ESR 31.3 Thunderbird 31.3 Security researcher Kent Howard reported an Apple issue present in OS X 10.10 (Yosemite) where log files are created by the CoreGraphics framework of OS X in the /tmp local directory. These log files contain a record of all inputs into Mozilla programs during their operation. In versions of OS X from versions 10.6 through 10.9, the CoreGraphics had this logging ability but it was turned off by default. In OS X 10.10, this logging was turned on by default for some applications that use a custom memory allocator, such as jemalloc , because of an initialization bug in the framework. This issue has bee...

Linked on 2014-12-10 23:55:29 | Similar Links