The X Window System contains a flaw that may allow a remote attacker to access arbitrary X sessions. The problem is that the system rand() function, used to generate MIT-MAGIC-COOKIE-1 keys when DES is not available, is weak on some systems. It is possible that the flaw may allow to obtain passwords and/or execute commands resulting in a loss of confidentiality and/or integrity.