CVE-2009-1573
EPSS 0.07%
Description
xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.
How to fix CVE-2009-1573
To remediate CVE-2009-1573, upgrade the affected package to a fixed version below.
- Debian/xorg-server—upgrade to 2:1.6.1.901-3 or later
Is CVE-2009-1573 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2:1.6.1.901-3