Red Hat Inc. Information for VU#911505
pam_xauth may insecurely forward "X MIT-Magic-Cookies" to new sessions
- Vendor Information Help Date Notified:
- Statement Date:
- Date Updated: 07 May 2003
Red Hat Linux, prior to version 9, and Red Hat Enterprise Linux ship with a pam_xauth package vulnerable to this issue. Updated packages are available along with our advisory at the URLs below. Users of the Red Hat Network can update their systems using the 'up2date' tool.
The vendor has not provided us with any further information regarding this vulnerability.
The CERT/CC has no additional comments at this time.
If you have feedback, comments, or additional information about this vulnerability, please send us email.