Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-2625

Опубликовано: 27 июл. 2018
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 2.1
CVSS3: 6.5

Описание

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

РелизСтатусПримечание
artful

ignored

end of life
bionic

released

1:1.1.2-3
cosmic

ignored

end of life
devel

released

1:1.1.2-3
disco

released

1:1.1.2-3
eoan

released

1:1.1.2-3
esm-infra-legacy/trusty

released

1:1.1.1-1ubuntu0.1~esm1
esm-infra/bionic

released

1:1.1.2-3
esm-infra/focal

released

1:1.1.2-3
esm-infra/xenial

released

1:1.1.2-1.1ubuntu0.1~esm1

Показывать по

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
redhat
больше 8 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
nvd
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

CVSS3: 6.5
debian
больше 7 лет назад

It was discovered that libXdmcp before 1.1.2 including used weak entro ...

suse-cvrf
больше 8 лет назад

Security update for libXdmcp

suse-cvrf
почти 8 лет назад

Security update for libXdmcp

EPSS

Процентиль: 12%
0.0004
Низкий

2.1 Low

CVSS2

6.5 Medium

CVSS3

Уязвимость CVE-2017-2625