XFce vulnerable to local X session hijacking (Patch available)
8 Nov. 2000
Summary
XFce is a window manager/desktop environment for the X Windows system. Versions of XFce prior to 3.52 contain a startup script that incorrectly allows access to the X display to all other users on the local system. Those users are able to monitor and control the contents of the display window as well as monitoring input from keyboard and mouse devices. For example, this allows them to monitor password phrases typed into a terminal window. We reported about this vulnerability in our previous article: XFce dangerous defaults (package problem). FreeBSD has now released a patch that corrects this problem.
4) Use the portcheckout utility to automate option (3) above. The portcheckout port is available in /usr/ports/devel/portcheckout or the package can be obtained from: