Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvmx-9h9q-8hmw

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

EPSS

Процентиль: 23%
0.00077
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
redhat
почти 9 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
nvd
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
debian
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entro ...

suse-cvrf
больше 8 лет назад

Security update for libXdmcp

EPSS

Процентиль: 23%
0.00077
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-331