UCF STIG Viewer Logo

The .Xauthority utility must only permit access to authorized hosts.


Overview

Finding ID Version Rule ID IA Controls Severity
V-216313 SOL-11.1-020550 SV-216313r603267_rule Medium
Description
If unauthorized clients are permitted access to the X server, a user's X session may be compromised.
STIG Date
Solaris 11 SPARC Security Technical Implementation Guide 2022-11-18

Details

Check Text ( C-17549r371027_chk )
If X Display Manager (XDM) is not used on the system, this is not applicable.

Determine if XDM is running.

Procedure:
# ps -ef | grep xdm

Check the X Window system access is limited to authorized clients.

Procedure:
# xauth
xauth> list

Ask the SA if the clients listed are authorized.

If any are not, this is a finding.
Fix Text (F-17547r371028_fix)
Remove unauthorized clients from the xauth configuration.

Procedure:
# xauth remove