Candidate: CVE-2009-1756 PublicDate: 2009-05-22 11:52:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1756 Description: SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=529306 Priority: low Discovered-by: Assigned-to: CVSS: Patches_slim: upstream_slim: needs-triage dapper_slim: DNE hardy_slim: ignored (reached end-of-life) intrepid_slim: needs-triage (reached end-of-life) jaunty_slim: ignored (reached end-of-life) karmic_slim: DNE lucid_slim: not-affected (1.3.1-2) maverick_slim: not-affected (1.3.1-2) natty_slim: not-affected (1.3.1-2) oneiric_slim: not-affected (1.3.1-2) devel_slim: not-affected (1.3.1-2)