LOW
SLiM: Potential X session hijacking (MITM)
Published May 22, 2009
2.1
LOWCVSS 2.0
EPSS 0.46%
Description
SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.
Affected products
No data.
- 1.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306 x_refsource_CONFIRMExploit
- http://osvdb.org/54583 vdb-entryx_refsource_OSVDB
- http://secunia.com/advisories/35132 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/38070 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.openwall.com/lists/oss-security/2009/05/18/2 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/35015 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2009-1756 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=501562 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2009-1751 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/50611 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2009-1756
- https://www.cve.org/CVERecord?id=CVE-2009-1756
- https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00000.html vendor-advisoryx_refsource_FEDORA
- https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00009.html vendor-advisoryx_refsource_FEDORA
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published May 22, 2009
Updated Aug 7, 2024
Reserved May 21, 2009
Link CVE-2009-1756
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2009-1751 Assigner mitre
Published May 22, 2009
Updated Aug 7, 2024
Exploited since n/a
Link EUVD-2009-1751