CVE-2009-1573
N/A
N/A
Summary
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.openwall.com/lists/oss-security/2009/05/05/2
- http://www.openwall.com/lists/oss-security/2009/05/05/4
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678
- http://secunia.com/advisories/39834
- http://www.securityfocus.com/bid/34828
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50348
- http://www.vupen.com/english/advisories/2010/1185
- http://www.ubuntu.com/usn/USN-939-1
References
- http://www.openwall.com/lists/oss-security/2009/05/05/2
- http://www.openwall.com/lists/oss-security/2009/05/05/4
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678
- http://secunia.com/advisories/39834
- http://www.securityfocus.com/bid/34828
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50348
- http://www.vupen.com/english/advisories/2010/1185
- http://www.ubuntu.com/usn/USN-939-1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.