First published: Wed May 06 2009(Updated: )
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Debian GNU/Linux | ||
Fedora | =10 | |
Ubuntu BusyBox Static | ||
branden robinson xvfb-run | =1.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-1573 has a medium severity rating due to the potential for local privilege escalation.
To fix CVE-2009-1573, you should update the xvfb-run package to a version that does not expose the MCOOKIE on the command line.
CVE-2009-1573 affects local users on Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems.
The impact of CVE-2009-1573 is that local users can gain elevated privileges by accessing the MCOOKIE from the command line.
CVE-2009-1573 was reported in May 2009.