VulnerabilityModified
CVE-2009-1573
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
MEDIUM 4.6EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.46% probability · 38th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- debian/debian linux · redhat/fedora · ubuntu/linux · branden robinson/xvfb-run
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678Exploit, Vendor Advisory
- http://secunia.com/advisories/39834
- http://www.openwall.com/lists/oss-security/2009/05/05/2
- http://www.openwall.com/lists/oss-security/2009/05/05/4
- http://www.securityfocus.com/bid/34828
- http://www.ubuntu.com/usn/USN-939-1
- http://www.vupen.com/english/advisories/2010/1185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50348
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678Exploit, Vendor Advisory
- http://secunia.com/advisories/39834
- http://www.openwall.com/lists/oss-security/2009/05/05/2
- http://www.openwall.com/lists/oss-security/2009/05/05/4
- http://www.securityfocus.com/bid/34828
- http://www.ubuntu.com/usn/USN-939-1
- http://www.vupen.com/english/advisories/2010/1185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50348
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.