CVE-2009-1573
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
- Debian Debian Linux
- All versions
- Redhat Fedora
- = 10
- Ubuntu Linux
- All versions
- Branden Robinson Xvfb-run
- = 1.6.1
- CVSS 2.0
- 4.6 MEDIUM
- EPSS
- 0.5% (38th percentile)
- Weakness
- CWE-264
- NVD status
- Modified
- Published
- 2009-05-06
CVE-2009-1573 at NVD
No indexed exploits for CVE-2009-1573 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2009-1573 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.