Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2626

Опубликовано: 27 июл. 2018
Источник: nvd
CVSS3: 5.2
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freedesktop:libice:*:*:*:*:*:*:*:*
Версия до 1.0.9 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:7.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:7.0:*:*:*:*:*:*:*

EPSS

Процентиль: 8%
0.00032
Низкий

5.2 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-331
CWE-331

Связанные уязвимости

CVSS3: 5.2
ubuntu
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
redhat
больше 8 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS3: 5.2
debian
больше 7 лет назад

It was discovered that libICE before 1.0.9-8 used a weak entropy to ge ...

suse-cvrf
больше 8 лет назад

Security update for libICE

suse-cvrf
почти 8 лет назад

Security update for libICE

EPSS

Процентиль: 8%
0.00032
Низкий

5.2 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-331
CWE-331