Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of XFCE 3.5.1 bypasses the Xauthority access control mechanism with an "xhost + localhost" command in the xinitrc program, which allows local users to sniff X Windows traffic and gain privileges.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
XFCE xinitrc权限提升漏洞
Vulnerability Description
XFCE 3.5.1的默认配置会通过xinitrc程序中的“xhost + localhost”命令绕过Xauthority访问控制机制,本地用户可以利用该漏洞侦测X Windows通信并获取权限。
CVSS Information
N/A
Vulnerability Type
N/A