<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=5538&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / X.Org Security Advisory: Security issue in the X server]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=5538</link>
		<description><![CDATA[The most recent posts in X.Org Security Advisory: Security issue in the X server.]]></description>
		<lastBuildDate>Sun, 16 Apr 2023 20:18:04 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41898#p41898</link>
			<description><![CDATA[<p>TIA, </p><p>/etc/inittab</p><div class="codebox"><pre class="vscroll"><code># /etc/inittab: init(8) configuration.
# $Id: inittab,v 1.91 2002/01/25 13:35:21 miquels Exp $

# The default runlevel.
id:2:initdefault:

# Boot-time system configuration/initialization script.
# This is run first except when booting in emergency (-b) mode.
si::sysinit:/etc/init.d/rcS

# What to do in single-user mode.
~~:S:wait:/sbin/sulogin --force

# /etc/init.d executes the S and K scripts upon change
# of runlevel.
#
# Runlevel 0 is halt.
# Runlevel 1 is single-user.
# Runlevels 2-5 are multi-user.
# Runlevel 6 is reboot.

l0:0:wait:/etc/init.d/rc 0
l1:1:wait:/etc/init.d/rc 1
l2:2:wait:/etc/init.d/rc 2
l3:3:wait:/etc/init.d/rc 3
l4:4:wait:/etc/init.d/rc 4
l5:5:wait:/etc/init.d/rc 5
l6:6:wait:/etc/init.d/rc 6
# Normally not reached, but fallthrough in case of emergency.
z6:6:respawn:/sbin/sulogin --force

# What to do when CTRL-ALT-DEL is pressed.
ca:12345:ctrlaltdel:/sbin/shutdown -t1 -a -r now

# Action on special keypress (ALT-UpArrow).
#kb::kbrequest:/bin/echo &quot;Keyboard Request--edit /etc/inittab to let this work.&quot;

# What to do when the power fails/returns.
pf::powerwait:/etc/init.d/powerfail start
pn::powerfailnow:/etc/init.d/powerfail now
po::powerokwait:/etc/init.d/powerfail stop

# /sbin/getty invocations for the runlevels.
#
# The &quot;id&quot; field MUST be the same as the last
# characters of the device (after &quot;tty&quot;).
#
# Format:
#  &lt;id&gt;:&lt;runlevels&gt;:&lt;action&gt;:&lt;process&gt;
#
# Note that on most Debian systems tty7 is used by the X Window System,
# so if you want to add more getty&#039;s go ahead but skip tty7 if you run X.
#
1:2345:respawn:/sbin/getty --noclear 38400 tty1
2:23:respawn:/sbin/getty 38400 tty2
3:23:respawn:/sbin/getty 38400 tty3
4:23:respawn:/sbin/getty 38400 tty4
5:23:respawn:/sbin/getty 38400 tty5
6:23:respawn:/sbin/getty 38400 tty6

# Example how to put a getty on a serial line (for a terminal)
#
#T0:23:respawn:/sbin/getty -L ttyS0 9600 vt100
#T1:23:respawn:/sbin/getty -L ttyS1 9600 vt100
#
# or on a USB serial line
#U0:23:respawn:/sbin/getty -L ttyUSB0 9600 vt100

# Example how to put a getty on a modem line.
#
#T3:23:respawn:/sbin/mgetty -x0 -s 57600 ttyS3

# Example for systemd-nspawn
# Only /dev/console exists inside nspawn, so we need a getty on that.
# Also make sure to comment out the gettys on tty* above.
#C0:2345:respawn:/sbin/getty -8 --noclear --keep-baud console 115200,38400,9600</code></pre></div><p>That&#039;s it... I dont remember modifying it.</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Sun, 16 Apr 2023 20:18:04 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41898#p41898</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41897#p41897</link>
			<description><![CDATA[<div class="quotebox"><cite>GlennW wrote:</cite><blockquote><div><p>Well, I got stuck this time, no tty&#039;s and a non-responsive keys and screen.</p><p>Why do I have no tty&#039;s?</p><p>Even now after a re-config to get the gui again and still no tty&#039;s. ona day at a time...</p></div></blockquote></div><p>Please post a copy of your </p><div class="codebox"><pre><code> /etc/inittab </code></pre></div><p> ?</p>]]></description>
			<author><![CDATA[dummy@example.com (MLEvD)]]></author>
			<pubDate>Sun, 16 Apr 2023 14:43:44 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41897#p41897</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41788#p41788</link>
			<description><![CDATA[<p>Well, I got stuck this time, no tty&#039;s and a non-responsive keys and screen.</p><p>Why do I have no tty&#039;s?</p><p>Even now after a re-config to get the gui again and still no tty&#039;s. ona day at a time...</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Thu, 06 Apr 2023 23:44:36 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41788#p41788</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41784#p41784</link>
			<description><![CDATA[<div class="quotebox"><cite>thierrybo wrote:</cite><blockquote><div><p>So the last line of your <strong>.xsession</strong> should just be:</p><div class="codebox"><pre><code>exec /usr/bin/&lt;WM&gt;</code></pre></div></div></blockquote></div><p>Hello. Should not be </p><div class="codebox"><pre><code>.xsession</code></pre></div><p> but </p><div class="codebox"><pre><code>.xsessionrc</code></pre></div><p>The Debian reference manual describes how the defaults work: </p><div class="quotebox"><blockquote><div><p>If the user has a ~/.xsessionrc file, read it.<br />If a specific session was selected in the DM (GDM, KDM, WDM, LightDM, ...) , run it.</p><p>Otherwise, if the user has a ~/.xsession or ~/.Xsession file, run it.</p><p>Otherwise, if the /usr/bin/x-session-manager command exists, run it.</p><p>Otherwise, if the /usr/bin/x-window-manager command exists, run it.</p><p>Otherwise, if the /usr/bin/x-terminal-emulator command exists, run it.</p></div></blockquote></div><p>This file should be executable. Here is example of </p><div class="codebox"><pre><code>.xsessionrc </code></pre></div><div class="codebox"><pre><code>#!/bin/bash

# Load resources

xrdb ~/.Xresources

setxkbmap -layout &quot;us,lt,ru&quot; -option &quot;grp:menu_toggle&quot;

picom --config ~/.config/picom/picom.conf &amp;

exec xmonad</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (stopAI)]]></author>
			<pubDate>Thu, 06 Apr 2023 12:06:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41784#p41784</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41780#p41780</link>
			<description><![CDATA[<p>This is my third time reading through this thread and I&#039;d like to THANK YOU ALL!</p><p>Some of this tech has escaped me for a long time and I&#039;m slowly putting the jigsaw puzzle pieces into position.</p><p>I like the bling but I want the security.</p><p>regards Glenn</p>]]></description>
			<author><![CDATA[dummy@example.com (GlennW)]]></author>
			<pubDate>Thu, 06 Apr 2023 01:17:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41780#p41780</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41137#p41137</link>
			<description><![CDATA[<div class="quotebox"><cite>fsmithred wrote:</cite><blockquote><div><p>lxdm and sddm both run X as root. To check that, run </p><div class="codebox"><pre><code>ps aux |grep X</code></pre></div></div></blockquote></div><p>Thanks for this! It looks like I&#039;ll have to give it some thought. I would be interested in more information on this topic and strategies for improvement.</p>]]></description>
			<author><![CDATA[dummy@example.com (jue-gen)]]></author>
			<pubDate>Thu, 16 Feb 2023 12:25:43 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41137#p41137</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41135#p41135</link>
			<description><![CDATA[<div class="quotebox"><cite>jue-gen wrote:</cite><blockquote><div><div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p> ... The default Xfce desktop for Devuan uses SLiM or LightDM and both run X under the root user so both are vulnerable to this exploit.</p><p>Starting the desktop via GDM or <span class="bbc">startx</span> will cause X to be run under the normal user and so avoid this vulnerability completely. ... )</p></div></blockquote></div><p>Perhaps I have not understood the problem correctly. SLiM or LightDM is clear. But I am thinking about it:<br />How is it with SDDM?<br />When I start Plasma Wayland, that is o.k.<br />But if I start e.g. LXDE with SDDM, how is that.</p></div></blockquote></div><p>lxdm and sddm both run X as root. To check that, run </p><div class="codebox"><pre><code>ps aux |grep X</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (fsmithred)]]></author>
			<pubDate>Thu, 16 Feb 2023 12:10:45 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41135#p41135</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41130#p41130</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p> ... The default Xfce desktop for Devuan uses SLiM or LightDM and both run X under the root user so both are vulnerable to this exploit.</p><p>Starting the desktop via GDM or <span class="bbc">startx</span> will cause X to be run under the normal user and so avoid this vulnerability completely. ... )</p></div></blockquote></div><p>Perhaps I have not understood the problem correctly. SLiM or LightDM is clear. But I am thinking about it:<br />How is it with SDDM?<br />When I start Plasma Wayland, that is o.k.<br />But if I start e.g. LXDE with SDDM, how is that.</p>]]></description>
			<author><![CDATA[dummy@example.com (jue-gen)]]></author>
			<pubDate>Thu, 16 Feb 2023 07:33:17 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41130#p41130</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41045#p41045</link>
			<description><![CDATA[<div class="quotebox"><cite>hunter0one wrote:</cite><blockquote><div><p> ... I like KDE applications, I do not like KDE Plasma. ...</p></div></blockquote></div><p><strong>Yes, I can understand that very well.</strong><br />Wayland is apparently more secure. By the way, I liked to use KDE applications in LXDE or Xfce. Of course it was also very nice in LXQt. Now I came back to KDE (<em>I started with KDE in 2001 [SuSE 7.2]</em>) because I wanted Wayland and I like the KDE applications. Right now I like it quite a bit.<br />Have a nice rest of the weekend - best regards<br /><strong>Addendum:</strong> in continuous use, however, I now actually notice some problems. For example, the taskbar is gone from time to time, nothing can be inserted from the cache, etc. In LXQt, which I use in parallel on the same computer, these problems do not occur ... but there again I have no Wayland <img src="https://dev1galaxy.org/img/smilies/sad.png" width="15" height="15" alt="sad" /></p>]]></description>
			<author><![CDATA[dummy@example.com (jue-gen)]]></author>
			<pubDate>Sat, 11 Feb 2023 19:41:27 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41045#p41045</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41027#p41027</link>
			<description><![CDATA[<div class="quotebox"><cite>jue-gen wrote:</cite><blockquote><div><div class="quotebox"><cite>hunter0one wrote:</cite><blockquote><div><p> ... I just stuck with KDE.</p></div></blockquote></div><p>I always had trouble with KDE Plasma and Wayland. I&#039;ve cursed it and wished it to hell. But your post triggered me yesterday to try it again (Daedalus).</p></div></blockquote></div><p>I should rephrase my use of KDE. I like KDE applications, I do not like KDE Plasma. I can&#039;t stand the flat Breeze theme and similar to GNOME&#039;s Adwaita it sticks to everything. Trying to make Plasma look a bit more like pre-Plasma is hopeless. I hope <a href="https://apps.kde.org/liquidshell/" rel="nofollow">LiquidShell</a> gets developed more and makes its way into Devuan one day (who knows, I could package it). I typically use Trinity desktop, but the really old Qt version and inability to keep up like MATE has driven me away.</p><p>The newer Plasma versions after Chimaera have improved Wayland support by a lot. I&#039;m ready to see what Daedulus will bring, if I&#039;m still running Plasma by then..</p>]]></description>
			<author><![CDATA[dummy@example.com (hunter0one)]]></author>
			<pubDate>Sat, 11 Feb 2023 14:15:14 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41027#p41027</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=41019#p41019</link>
			<description><![CDATA[<div class="quotebox"><cite>hunter0one wrote:</cite><blockquote><div><p> ... I just stuck with KDE.</p></div></blockquote></div><p>I always had trouble with KDE Plasma and Wayland. I&#039;ve cursed it and wished it to hell. But your post triggered me yesterday to try it again (Daedalus). At least no crashes I noticed. And Wayland runs. I&#039;m still reluctant, but I&#039;m also optimistic and hope that it will be a usable and recommendable system when Dadalus becomes stable....</p>]]></description>
			<author><![CDATA[dummy@example.com (jue-gen)]]></author>
			<pubDate>Sat, 11 Feb 2023 09:48:34 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=41019#p41019</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40995#p40995</link>
			<description><![CDATA[<div class="quotebox"><cite>Head_on_a_Stick wrote:</cite><blockquote><div><p>Everybody loves GNOME, right?</p></div></blockquote></div><p>LOL, don&#039;t we all?</p><p>Really, I&#039;ve been having a desktop identity crisis the past 2 weeks. I just stuck with KDE.</p>]]></description>
			<author><![CDATA[dummy@example.com (hunter0one)]]></author>
			<pubDate>Fri, 10 Feb 2023 17:16:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40995#p40995</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40976#p40976</link>
			<description><![CDATA[<p>GNOME works fine with flatpaks, they&#039;re even recommended by the developers. The Wayland desktop is the default for Debian bullseye. Everybody loves GNOME, right?</p>]]></description>
			<author><![CDATA[dummy@example.com (Head_on_a_Stick)]]></author>
			<pubDate>Thu, 09 Feb 2023 17:38:12 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40976#p40976</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40974#p40974</link>
			<description><![CDATA[<p>I would use Wayland but in the latest stable its buggy as hell on KDE, especially with Flatpaks.</p>]]></description>
			<author><![CDATA[dummy@example.com (hunter0one)]]></author>
			<pubDate>Thu, 09 Feb 2023 16:20:24 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40974#p40974</guid>
		</item>
		<item>
			<title><![CDATA[Re: X.Org Security Advisory: Security issue in the X server]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=40964#p40964</link>
			<description><![CDATA[<p>startx /usr/bin/wm or startx /usr/local/bin/wm then chuck it in my .bashrc with an one letter alias then fire up &quot;auto&quot; again another alias auto=/path/to/autostart.sh. At least until I&#039;m happy everything works as it should... I guess I&#039;m a Cave Man. :-)</p>]]></description>
			<author><![CDATA[dummy@example.com (Kelsoo)]]></author>
			<pubDate>Wed, 08 Feb 2023 17:18:41 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=40964#p40964</guid>
		</item>
	</channel>
</rss>
