CVE-2015-7327

Publication date 24 September 2015

Last updated 24 July 2024


Ubuntu priority

Description

Mozilla Firefox before 41.0 does not properly restrict the availability of High Resolution Time API times, which allows remote attackers to track last-level cache access, and consequently obtain sensitive information, via crafted JavaScript code that makes performance.now calls.

Read the notes from the security team

Status

Package Ubuntu Release Status
firefox 15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
thunderbird 15.04 vivid
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected

Notes


seth-arnold

Windows-specific issue doesn't affect Linux or OS X


Access our resources on patching vulnerabilities