Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

PAM pam_xauth Module Unintended X Session Cookie Access Vulnerability

A vulnerability has been discovered on default RedHat Linux installations which potentially allows a malicious local user to obtain elevated privileges. The problem occurs when a user is running the su utility, in conjunction with the PAM pam_xauth module, to assume the identity of another user. The issue occurs due to the use of a temporary .xauth-file accessible by the real user whose identity is being assumed. Exploiting this issue may allow an attacker to connect to the X session of the user executing su.







 

Privacy Statement
Copyright 2008, SecurityFocus