CNCVE编号:CNCVE-20001059 CVE编号:CVE-2000-1059 安全级别:中 漏洞中文描述: 在Mandrake Linux 7.1和7.0中的Xsession文件的默认配置以“xhost + localhost”命令绕过Xauthority访问控制机制,允许本地用户跟踪X Windows事件以及得到权限。 漏洞英文描述: The default configuration of the Xsession file in Mandrake Linux 7.1 and 7.0 bypasses the Xauthority access control mechanism with an "xhost + localhost" command, which allows local users to sniff X Windows events and gain privileges. 漏洞参考: 系统类型:其他 漏洞类型:其他