This server appears to have been closed source, and I assume the source is lost. My bet is that OpenBSD's X server has a far better security design, as the server itself no longer runs as root. The aggressive free() also exposed use-after-free bugs never before seen, and OpenBSD has superior mitigations for rop gadget abuse, aslr everywhere, and other exploits beyond the imagination of 1989. The paper documents probl…
The author is @Java4First on Twitter. Give it a shot.