| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.64122 |
| Category: | FreeBSD Local Security Checks |
| Title: | FreeBSD Ports: slim |
| Summary: | FreeBSD Ports: slim |
| Description: | The remote host is missing an update to the system as announced in the referenced advisory. The following package is affected: slim CVE-2009-1756 SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments. Solution: Update your system with the appropriate patches or software upgrades. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306 http://www.vuxml.org/freebsd/80f13884-4d4c-11de-8811-0030843d3802.html |
| Cross-Ref: |
BugTraq ID: 35015 Common Vulnerability Exposure (CVE) ID: CVE-2009-1756 http://www.openwall.com/lists/oss-security/2009/05/18/2 https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00000.html https://www.redhat.com/archives/fedora-package-announce/2010-January/msg00009.html http://www.securityfocus.com/bid/35015 http://osvdb.org/54583 http://secunia.com/advisories/35132 http://secunia.com/advisories/38070 XForce ISS Database: slim-xauthority-info-disclosure(50611) http://xforce.iss.net/xforce/xfdb/50611 |
| Copyright | Copyright (c) 2009 E-Soft Inc. http://www.securityspace.com |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|