UCF STIG Viewer Logo

The .Xauthority utility must only permit access to authorized hosts.


Overview

Finding ID Version Rule ID IA Controls Severity
V-226966 GEN005240 SV-226966r603265_rule Medium
Description
If unauthorized clients are permitted access to the X server, a user's X session may be compromised.
STIG Date
Solaris 10 SPARC Security Technical Implementation Guide 2020-12-04

Details

Check Text ( C-29128r485228_chk )
Check the X Window system access is limited to authorized clients.

Procedure:
# xauth
xauth> list

Ask the SA if the clients listed are authorized. If any are not, this is a finding.
Fix Text (F-29116r485229_fix)
Remove unauthorized clients from the xauth configuration.
# xauth remove