Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2625

Опубликовано: 27 июл. 2018
Источник: debian
EPSS Низкий

Описание

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libxdmcpfixed1:1.1.2-2package
libxdmcpno-dsawheezypackage

Примечания

  • https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/

EPSS

Процентиль: 12%
0.0004
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
redhat
больше 8 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
nvd
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

suse-cvrf
больше 8 лет назад

Security update for libXdmcp

suse-cvrf
почти 8 лет назад

Security update for libXdmcp

EPSS

Процентиль: 12%
0.0004
Низкий