Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jqp9-hwjj-p328

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

EPSS

Процентиль: 8%
0.00032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-331

Связанные уязвимости

CVSS3: 5.2
ubuntu
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
redhat
больше 8 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
nvd
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
debian
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to ge ...

suse-cvrf
больше 8 лет назад

Security update for libICE

EPSS

Процентиль: 8%
0.00032
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-331