Mandrake X session Local Xauthority...

- AV AC AU C I A
发布: 2000-09-29
修订: 2025-04-13

The X11 startup script shipped with Mandrake 7.1 (/etc/X11/Xsession) contains a line, "xhost + localhost", which disables the Xauthority mechanism for localhost, allowing any users' clients to connect to the X server from the local machine. This can be dangerous on multi-user systems since the other users can perform X-related attacks (keyword logging, window watching, etc.). This may indirectly lead to an elevation of priveleges (if the attacker logs the user su'ing to root, for example) or other compromises (ie if authenticating on another host is logged).

0%
暂无可用Exp或PoC
当前有0条受影响产品信息