Bug 592
Summary: | standard startx script allows any user to capture X events (and keystroke) from other users' windows | ||
---|---|---|---|
Product: | [Retired] Red Hat Linux | Reporter: | borgia |
Component: | XFree86 | Assignee: | Preston Brown <pbrown> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | medium | Docs Contact: | |
Priority: | high | ||
Version: | 5.2 | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 1999-01-18 22:20:47 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
borgia
1998-12-26 11:08:13 UTC
You might also consider using the mkxauth package A patch to use xauth in startx will be posted to the errata site. However, 5.2 will not incorporate this patch into XFree in an security update, because many people are not familiar with xauth but only xhost (no matter how wrong this is) and there will be much complaining from them if we change this. 6.0 will make the change. |