First published: Wed Jul 01 2015(Updated: )
The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
openSUSE openSUSE | =13.2 | |
X.org Xorg-server | =1.16.0 | |
X.org Xorg-server | =1.16.1 | |
X.org Xorg-server | =1.16.1.901 | |
X.org Xorg-server | =1.16.2 | |
X.org Xorg-server | =1.16.2.901 | |
X.org Xorg-server | =1.16.3 | |
X.org Xorg-server | =1.16.4 | |
X.org Xorg-server | =1.16.99.901 | |
X.org Xorg-server | =1.16.99.902 | |
X.org Xorg-server | =1.17.0 | |
X.org Xorg-server | =1.17.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.