The authentication setup in XWayland 1.16.x and 1.17.x before 1.17.2 starts the server in non-authenticating mode, which allows local users to read from or send information to arbitrary X11 clients via vectors involving a UNIX socket.
| Software | From | Fixed in |
|---|---|---|
| opensuse / opensuse | 13.2 | 13.2.x |
| x.org / xorg-server | 1.16.4 | 1.16.4.x |
| x.org / xorg-server | 1.17.1 | 1.17.1.x |
| x.org / xorg-server | 1.16.99.902 | 1.16.99.902.x |
| x.org / xorg-server | 1.16.99.901 | 1.16.99.901.x |
| x.org / x_server | 1.16.0 | 1.16.0.x |
| x.org / x_server | 1.16.1 | 1.16.1.x |
| x.org / x_server | 1.16.1.901 | 1.16.1.901.x |
| x.org / x_server | 1.16.2 | 1.16.2.x |
| x.org / x_server | 1.16.2.901 | 1.16.2.901.x |
| x.org / x_server | 1.16.3 | 1.16.3.x |
| x.org / x_server | 1.17.0 | 1.17.0.x |