Subject: Re: Weekly BSD Security Digest 2000/07/10 to 2000/07/16
To: None <tls@rek.tjls.com>
From: Perry E. Metzger <perry@wasabisystems.com>
List: tech-x11
Date: 07/24/2000 13:40:13
Thor Lancelot Simon <tls@rek.tjls.com> writes:
> An issue to be aware of that trips up many folks running X carefully is
> that this doesn't prevent *xdm* from listening to the network, allowing
> anyone who runs X -query foo.bar.com to talk to the XDM on foo.bar.com and
> attempt to exploit any vulnerabilities it may have.

True enough. Perhaps we need to write (and contribute back) a similar
hack for xdm. In virtually every setup, xdm does not need to talk to
the network -- the ones where it is useful are rare in our context.

--
Perry E. Metzger		perry@wasabisystems.com
--
Quality NetBSD Sales, Support & Service. http://www.wasabisystems.com/