Vulnerabilities > CVE-2000-1059 - Unspecified vulnerability in Mandrakesoft Mandrake Linux 7.0/7.1

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
mandrakesoft
nessus

Summary

The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges.

Vulnerable Configurations

Part Description Count
OS
Mandrakesoft
2

Nessus

NASL familyMandriva Local Security Checks
NASL idMANDRAKE_MDKSA-2000-052.NASL
descriptionA problem exists in the /etc/X11/Xsession file which disables the Xauthority mechanism of the localhost. This means that anyone logged into the localhost can arbitrarily connect to an X server running on the localhost. This is only a problem with systems that allow remote logins and is not a problem on systems that do not support remote logins or multiple users.
last seen2020-06-01
modified2020-06-02
plugin id61842
published2012-09-06
reporterThis script is Copyright (C) 2012-2019 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/61842
titleMandrake Linux Security Advisory : xinitrc (MDKSA-2000:052)