CVE-2009-1573

Publication date

2009-05-06 17:00:00

Family

mitre

State

PUBLISHED

Description

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.