slim: X session hijacking
Package(s): | slim | CVE #(s): | CVE-2009-1756 | ||||||||
Created: | January 4, 2010 | Updated: | September 9, 2010 | ||||||||
Description: | From the Red Hat bugzilla entry: Potential man-in-the-middle attack was found in SLiM (Simple Login Manager) due to improper processing of authorization information used in connection to the X server. A local attacker could use this flaw to hijack X session of the victim by overhearing of certain information, needed for proper extraction of authorization records. | ||||||||||
Alerts: |
|