Back to search
CVE-2017-2626
Published: Jul 27, 2018
Modified: Aug 5, 2024
PUBLISHED
CVSS v3.0
5.2
MEDIUM
Description
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
| Vendor | Product | Versions |
|---|---|---|
Xorg | libICE | affected 1.0.9-8 |
Weaknesses (CWE)
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
Low
References
GLSA-201704-03
vendor-advisory
x_refsource_GENTOO
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2626
x_refsource_CONFIRM
RHSA-2017:1865
vendor-advisory
x_refsource_REDHAT
1037919
vdb-entry
x_refsource_SECTRACK
96480
vdb-entry
x_refsource_BID
https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/
x_refsource_MISC
[oss-security] 20190714 Fwd: [ANNOUNCE] libICE 1.0.10
mailing-list
x_refsource_MLIST
[debian-lts-announce] 20191123 [SECURITY] [DLA 2002-1] libice security update
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now