Executive brief
A security flaw in HP-UX 9.x allows local users to bypass authorization checks for the X Window System. This could allow an unauthorized person with access to the system to view or interact with another user's graphical session, potentially leading to the theft of sensitive information or unauthorized actions. The issue stems from the system failing to properly enforce the Xauthority security mechanism under certain conditions.
Technical details
The vulnerability exists in the implementation of the Xauthority mechanism within HP-UX 9.x. Under specific, unnamed conditions, the system fails to enforce the standard X11 cookie-based authentication, leaving the X display accessible to any local user. An attacker with local shell access can exploit this to connect to the X server, monitor keystrokes, capture screen contents, or inject input into other users' sessions. This is a local privilege escalation/unauthorized access issue. While the advisory dates back to 1994, it highlights a failure in the transition from host-based to user-based (Xauthority) access control.
Affected products
- HP HP-UX 9.x
Timeline
- 1994-07-13: disclosed
- 1994-07-13: advisory