xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:02
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678 - Exploit, Vendor Advisory | |
References | () http://secunia.com/advisories/39834 - | |
References | () http://www.openwall.com/lists/oss-security/2009/05/05/2 - | |
References | () http://www.openwall.com/lists/oss-security/2009/05/05/4 - | |
References | () http://www.securityfocus.com/bid/34828 - | |
References | () http://www.ubuntu.com/usn/USN-939-1 - | |
References | () http://www.vupen.com/english/advisories/2010/1185 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/50348 - |
Information
Published : 2009-05-06 17:30
Updated : 2024-11-21 01:02
NVD link : CVE-2009-1573
Mitre link : CVE-2009-1573
CVE.ORG link : CVE-2009-1573
JSON object : View
Products Affected
ubuntu
- linux
redhat
- fedora
branden_robinson
- xvfb-run
debian
- debian_linux
CWE
CWE-264
Permissions, Privileges, and Access Controls