It was found that Xwayland allowed users to access a display even if it was started with the "-auth" option. Furthermore, current wayland compositors (including weston, mutter, and, probably, all others), neglect to start Xwayland with "-auth".
Upstream advisory: http://lists.x.org/archives/xorg-announce/2015-June/002611.html Upstream commits: http://cgit.freedesktop.org/xorg/xserver/commit/?id=c4534a38b68aa07fb82318040dc8154fb48a9588 http://cgit.freedesktop.org/xorg/xserver/commit/?id=4b4b9086d02b80549981d205fb1f495edc373538 http://cgit.freedesktop.org/xorg/xserver/commit/?id=76636ac12f2d1dbdf7be08222f80e7505d53c451
Statement: Not vulnerable. This issue did not affect the versions of xorg-x11-server as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Created xorg-x11-server tracking bugs for this issue: Affects: fedora-all [bug 1232131]