Executive brief
The X Window System server, which manages graphical displays on Unix-like systems, can be configured to disable all access controls. When this occurs, any user on the network can connect to the display, allowing them to monitor everything the user types and see what is on their screen. This can lead to the theft of passwords, sensitive data, and full takeover of the user's account.
Technical details
The X server's host-based access control mechanism can be completely disabled, typically through the 'xhost +' command or insecure default configurations in X server emulators. This vulnerability allows any remote attacker with network reachability to the X server (usually TCP port 6000) to connect without authentication. Once connected, an attacker can use X11 protocol features to sniff keystrokes (keylogging), capture screen contents, and inject input events into active windows. This effectively grants the attacker the same privileges as the user running the X session. Mitigation involves using the Xauthority (MIT-MAGIC-COOKIE) mechanism or tunneling X11 over SSH.
Affected products
- X.Org Foundation X Window System (X11) Server
Timeline
- 1997-07-01: disclosed: Initial NVD publication date
- 2003-07-18: advisory: CERT/CC vulnerability note published