CVE-2009-1573

N/A Unknown
Published: May 06, 2009 Modified: April 23, 2026
View on NVD

Description

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678
Source: cve@mitre.org
Exploit Vendor Advisory
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=526678
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit Vendor Advisory
http://secunia.com/advisories/39834
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2009/05/05/2
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.openwall.com/lists/oss-security/2009/05/05/4
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/34828
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/USN-939-1
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2010/1185
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/50348
Source: af854a3a-2127-422b-91ae-364da2661108

16 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
0.1%
21th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

ubuntu branden_robinson redhat debian