Back to search
CVE-2009-1573
Published: May 6, 2009
Modified: Aug 7, 2024
PUBLISHED
Description
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20090505 CVE id request: Debian/Ubuntu specific issue in xvfb-run (xorg)
mailing-list
x_refsource_MLIST
[oss-security] 20090505 Re: CVE id request: Debian/Ubuntu specific issue in xvfb-run (xorg)
mailing-list
x_refsource_MLIST
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678
x_refsource_CONFIRM
39834
third-party-advisory
x_refsource_SECUNIA
34828
vdb-entry
x_refsource_BID
xvfbrun-magiccookie-info-disclosure(50348)
vdb-entry
x_refsource_XF
ADV-2010-1185
vdb-entry
x_refsource_VUPEN
USN-939-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now