CVE
- Id
- 240
- CVE No.
- CVE-1999-0241
- Status
- Candidate
- Description
- Guessable magic cookies in X Windows allows remote attackers to execute commands, e.g. through xterm.
- Phase
- Modified (19990925-01)
- Votes
- ACCEPT(3) Hill, Northcutt, Proctor | MODIFY(2) Frech, Prosser | NOOP(1) Baker | REVIEWING(1) Christey
- Comments
- Frech> Also add to references: | XF:sol-mkcookie | Prosser> additional source | Bugtraq | "X11 cookie hijacker" | http://www.securityfocus.com | Christey> The cookie hijacker thread has to do with stealing cookies | through a file with bad permissions. I"m not sure the | X-Force reference identifies this problem either. | Christey> CIAC:G-04 | URL:http://ciac.llnl.gov/ciac/bulletins/g-04.shtml | SGI:19960601-01-I | URL:ftp://patches.sgi.com/support/free/security/advisories/19960601-01-I | CERT:VB-95:08