xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
References
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2009-05-06 10:30
Updated : 2017-08-16 18:30
NVD link : CVE-2009-1573
Mitre link : CVE-2009-1573
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
debian
- debian_linux
ubuntu
- linux
branden_robinson
- xvfb-run
redhat
- fedora