Security Advisory

CVE-2009-1573

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2009-05-06 17:00:00
Last updated 2024-08-07 05:20:34
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.