Fedora Account System
Red Hat Associate
Red Hat Customer
Security researcher David Chan reported that Mozilla's mozTCPSocket implementation could leak data past the end of an array allowing for the potential exposure of memory or private data to malicious servers. This feature is used by Firefox OS and is disabled by default in Firefox on other operating systems. Upstream bug: https://bugzilla.mozilla.org/show_bug.cgi?id=994337 External References: https://www.mozilla.org/en-US/security/advisories/mfsa2015-97/
Acknowledgements: Red Hat would like to thank the Mozilla project for reporting this issue. Upstream acknowledges David Chan as the original reporter.