[Full-disclosure] Re: A short warning on the X11 Editres protocol

From: Frank v Waveren (fvw.bugtraq_at_var.cx)
Date: 06/02/05

  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 731-1] New krb4 packages fix arbitrary code execution"
    Date: Thu, 2 Jun 2005 12:08:03 +0200
    To: Florian Weimer <fw@deneb.enyo.de>
    
    
    
    

    On Tue, May 31, 2005 at 11:37:37PM +0200, Florian Weimer wrote:
    > However, xterm is an Xt application and therefore speaks a
    > long-forgotten protocol called Editres. As a result, any Editres
    > client (such as "editres") can instruct an xterm window to change its
    > allowSendEvents setting. After that, it's possible to send
    > synthesized events to the xterm window and hijack the terminal.
    And even if it weren't toggleable with editres, there's still the
    XTEST extension which seems to be pretty omnipresent these days.
    Basically, you shouldn't be mixing privileges in one X session (even
    using the security extension it's generally something you want to
    avoid, design-wise).

    -- 
    Frank v Waveren                                      Fingerprint: BDD7 D61E
    fvw@[var.cx|stack.nl] ICQ#10074100                      5D39 CF05 4BFC F57A
    Public key: hkp://wwwkeys.pgp.net/468D62C8              FA00 7D51 468D 62C8
    
    

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.grok.org.uk/full-disclosure-charter.html
    Hosted and sponsored by Secunia - http://secunia.com/



  • Next message: Martin Schulze: "[Full-disclosure] [SECURITY] [DSA 731-1] New krb4 packages fix arbitrary code execution"

    Relevant Pages

    • [Full-disclosure] A short warning on the X11 Editres protocol
      ... The xterm manual page contains a strongly worded warning about the ... | allowSendEvents ... | Specifies whether or not synthetic key and button events ... As a result, any Editres ...
      (Full-Disclosure)
    • A short warning on the X11 Editres protocol
      ... The xterm manual page contains a strongly worded warning about the ... | allowSendEvents ... | Specifies whether or not synthetic key and button events ... As a result, any Editres ...
      (Bugtraq)
    • Re: A short warning on the X11 Editres protocol
      ... As a result, any Editres ... > allowSendEvents setting. ... > synthesized events to the xterm window and hijack the terminal. ... XTEST extension which seems to be pretty omnipresent these days. ...
      (Bugtraq)