The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an xhost + localhost command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Xfce | Xfree86_project | 3.5.1 (including) | 3.5.1 (including) |