Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2626

Опубликовано: 27 июл. 2018
Источник: debian
EPSS Низкий

Описание

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libicefixed2:1.0.9-2package
libiceno-dsawheezypackage

Примечания

  • https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/

EPSS

Процентиль: 8%
0.00032
Низкий

Связанные уязвимости

CVSS3: 5.2
ubuntu
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
redhat
больше 8 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
nvd
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

suse-cvrf
больше 8 лет назад

Security update for libICE

suse-cvrf
почти 8 лет назад

Security update for libICE

EPSS

Процентиль: 8%
0.00032
Низкий