Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2625

Опубликовано: 28 фев. 2017
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

It was discovered that libXdmcp used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

Отчет

Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libXdmcpWill not fix
Red Hat Enterprise Linux 6libXdmcpWill not fix
Red Hat Enterprise Linux 7libdrmFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libepoxyFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libevdevFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libfontencFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libICEFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libinputFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libvdpauFixedRHSA-2017:186501.08.2017
Red Hat Enterprise Linux 7libwacomFixedRHSA-2017:186501.08.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=1424987libXdmcp: weak entropy usage for session keys

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
nvd
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
debian
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entro ...

suse-cvrf
больше 8 лет назад

Security update for libXdmcp

suse-cvrf
почти 8 лет назад

Security update for libXdmcp

EPSS

Процентиль: 12%
0.0004
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2017-2625