// For flags

CVE-2009-1573

 

Severity Score

4.6
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

xvfb-run 1.6.1 in Debian GNU/Linux, Ubuntu, Fedora 10, and possibly other operating systems place the magic cookie (MCOOKIE) on the command line, which allows local users to gain privileges by listing the process and its arguments.

xvfb-run v1.6.1 en Debian GNU/Linux, Ubuntu, Fedora 10 y posiblemente otros sistemas operativos, ubican la magic cookie (MCOOKIE) en la lĂ­nea de comandos, lo que permite a usuarios locales obtener privilegios listando los procesos y sus argumentos.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2009-05-06 CVE Reserved
  • 2009-05-06 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-07 CVE Updated
  • 2024-08-07 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
*-
Affected
in Branden Robinson
Search vendor "Branden Robinson"
Xvfb-run
Search vendor "Branden Robinson" for product "Xvfb-run"
1.6.1
Search vendor "Branden Robinson" for product "Xvfb-run" and version "1.6.1"
-
Affected
Redhat
Search vendor "Redhat"
Fedora
Search vendor "Redhat" for product "Fedora"
10
Search vendor "Redhat" for product "Fedora" and version "10"
-
Affected
in Branden Robinson
Search vendor "Branden Robinson"
Xvfb-run
Search vendor "Branden Robinson" for product "Xvfb-run"
1.6.1
Search vendor "Branden Robinson" for product "Xvfb-run" and version "1.6.1"
-
Affected
Ubuntu
Search vendor "Ubuntu"
Linux
Search vendor "Ubuntu" for product "Linux"
*-
Affected
in Branden Robinson
Search vendor "Branden Robinson"
Xvfb-run
Search vendor "Branden Robinson" for product "Xvfb-run"
1.6.1
Search vendor "Branden Robinson" for product "Xvfb-run" and version "1.6.1"
-
Affected