Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of the pam_xauth module forwards MIT-Magic-Cookies to new X sessions, which could allow local users to gain root privileges by stealing the cookies from a temporary .xauth file, which is created with the original user's credentials after root uses su.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PAM pam_xauth模块未计划X会话cookie访问漏洞
Vulnerability Description
Pam_xauth模块的默认设置将MIT-Magic-Cookies转送到新X会话,本地用户可以利用该漏洞,通过从临时.xauth文件窃取cookie获取根权限,该文件在根使用su创建后具有原始用户的证书。
CVSS Information
N/A
Vulnerability Type
N/A