[39060] in bugtraq
Re: A short warning on the X11 Editres protocol
daemon@ATHENA.MIT.EDU (Frank v Waveren)
Thu Jun 2 14:54:07 2005
Date: Thu, 2 Jun 2005 12:08:03 +0200
From: Frank v Waveren <fvw.bugtraq@var.cx>
To: Florian Weimer <fw@deneb.enyo.de>
Cc: security-announce@lists.enyo.de, bugtraq@securityfocus.com,
full-disclosure@lists.grok.org.uk
Message-ID: <20050602100803.GA14767@var.cx>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="2fHTh5uZTiUOsy+g"
Content-Disposition: inline
In-Reply-To: <87ll5v84bi.fsf@deneb.enyo.de>
--2fHTh5uZTiUOsy+g
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
On Tue, May 31, 2005 at 11:37:37PM +0200, Florian Weimer wrote:
> However, xterm is an Xt application and therefore speaks a
> long-forgotten protocol called Editres. As a result, any Editres
> client (such as "editres") can instruct an xterm window to change its
> allowSendEvents setting. After that, it's possible to send
> synthesized events to the xterm window and hijack the terminal.
And even if it weren't toggleable with editres, there's still the
XTEST extension which seems to be pretty omnipresent these days.
Basically, you shouldn't be mixing privileges in one X session (even
using the security extension it's generally something you want to
avoid, design-wise).
--=20
Frank v Waveren Fingerprint: BDD7 D61E
fvw@[var.cx|stack.nl] ICQ#10074100 5D39 CF05 4BFC F57A
Public key: hkp://wwwkeys.pgp.net/468D62C8 FA00 7D51 468D 62C8
--2fHTh5uZTiUOsy+g
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFCntqD+gB9UUaNYsgRAot1AJ9UzPNX96T5vAnsQrF7PT252/WxVQCfVi7T
zdKlKxygmN2zDYQQ0a36IAU=
=pX4o
-----END PGP SIGNATURE-----
--2fHTh5uZTiUOsy+g--