xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2009/05/05/2 | mailing list |
http://www.openwall.com/lists/oss-security/2009/05/05/4 | mailing list |
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678 | exploit vendor advisory |
http://secunia.com/advisories/39834 | third party advisory |
http://www.securityfocus.com/bid/34828 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/50348 | vdb entry |
http://www.vupen.com/english/advisories/2010/1185 | vdb entry |
http://www.ubuntu.com/usn/USN-939-1 | vendor advisory |