DEBIAN-CVE-2009-1756

Source
https://security-tracker.debian.org/tracker/CVE-2009-1756
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2009-1756.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2009-1756
Upstream
Published
2009-05-22T11:52:40Z
Modified
2025-09-19T06:20:58Z
Summary
[none]
Details

SLiM Simple Login Manager 1.3.0 places the X authority magic cookie (mcookie) on the command line when invoking xauth from (1) app.cpp and (2) switchuser.cpp, which allows local users to access the X session by listing the process and its arguments.

References

Affected packages

Debian:11 / slim

Package

Name
slim
Purl
pkg:deb/debian/slim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / slim

Package

Name
slim
Purl
pkg:deb/debian/slim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / slim

Package

Name
slim
Purl
pkg:deb/debian/slim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-2

Ecosystem specific

{
    "urgency": "low"
}

Debian:14 / slim

Package

Name
slim
Purl
pkg:deb/debian/slim?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.1-2

Ecosystem specific

{
    "urgency": "low"
}