cbcvebase.
CVE-2009-1573
published 2009-05-06

CVE-2009-1573: xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows…

PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.46%
36.7th percentile
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.

Affected

7 ranges
VendorProductVersion rangeFixed in
branden_robinsonxvfb-run
debianxorg-server< xorg-server 2:1.6.1.901-3 (bookworm)xorg-server 2:1.6.1.901-3 (bookworm)
redhatfedora
x.orgxorg-server>= 0 < 2:1.6.1.901-32:1.6.1.901-3
x.orgxorg-server>= 0 < 2:1.6.1.901-32:1.6.1.901-3
x.orgxorg-server>= 0 < 2:1.6.1.901-32:1.6.1.901-3
x.orgxorg-server>= 0 < 2:1.6.1.901-32:1.6.1.901-3

CVSS provenance

nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6LOW
vendor_redhat4.6MEDIUM
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.