Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2002-1160
Description:The default configuration of the pam_xauth module forwards MIT-Magic- Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.
Test IDs: 1.3.6.1.4.1.25623.1.0.51436   1.3.6.1.4.1.25623.1.0.50682   1.3.6.1.4.1.25623.1.0.50989  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2002-1160
BugTraq ID: 6753
http://www.securityfocus.com/bid/6753
Bugtraq: 20021214 BDT_AV200212140001: Insecure default: Using pam_xauth for su from sh-utils package (Google Search)
http://marc.info/?l=bugtraq&m=104431622818954&w=2
CERT/CC vulnerability note: VU#911505
http://www.kb.cert.org/vuls/id/911505
Conectiva Linux advisory: CLA-2003:693
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000693
http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:017
RedHat Security Advisories: RHSA-2003:028
http://www.redhat.com/support/errata/RHSA-2003-028.html
RedHat Security Advisories: RHSA-2003:035
http://www.redhat.com/support/errata/RHSA-2003-035.html
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/55760
XForce ISS Database: linux-pamxauth-gain-privileges(11254)
http://www.iss.net/security_center/static/11254.php




© 1998-2025 E-Soft Inc. All rights reserved.