FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2009-1756

This CVE name corresponds to:

Entered Topic
2009-05-30 slim -- local disclosure of X authority magic cookie

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2009-1756
Phase Assigned(20090521)

Description

SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.

References

Source Reference
MLIST [oss-security] 20090518 CVE id request: slim
CONFIRM http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306
FEDORA FEDORA-2009-13551
FEDORA FEDORA-2009-13552
BID 35015
OSVDB 54583
SECUNIA 35132
SECUNIA 38070
XF slim-xauthority-info-disclosure(50611)