187
VMScore

CVE-2017-2625

Published: 27/07/2018 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

It exists that libXdmcp prior to 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

x.org libxdmcp

redhat enterprise linux desktop 7.0

redhat enterprise linux workstation 7.0

redhat enterprise linux 7.0

redhat enterprise linux server 7.0

redhat enterprise linux server aus 7.4

redhat enterprise linux server eus 7.4

redhat enterprise linux server eus 7.5

Vendor Advisories

Debian Bug report logs - #856399 libxdmcp: CVE-2017-2625: Weak entropy usage for session keys in libxdm Package: src:libxdmcp; Maintainer for src:libxdmcp is Debian X Strike Force <debian-x@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 28 Feb 2017 15:54:02 UTC Severity: important ...
It was discovered that libXdmcp used weak entropy to generate session keys On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions ...

Exploits

Xorg suffers from privilege escalation, weak entropy, and use-after-free vulnerabilities ...

Mailing Lists

This issue was already disclosed at: wwwx41-dsecde/lab/advisories/x41-2017-001-xorg/ wwwopenwallcom/lists/oss-security/2017/02/28/3 This just upgrades the fix from a git commit/patch to a released tarball -Alan Coopersmith- alancoopersmith () oracle com XOrg Security Response Team - xorg-s ...

Github Repositories

Hack the box course

Linux Structure History Many events led up to creating the first Linux kernel and, ultimately, the Linux operating system (OS), starting with the Unix operating system's release by Ken Thompson and Dennis Ritchie (whom both worked for AT&T at the time) in 1970 The Berkeley Software Distribution (BSD) was released in 1977, but since it contained the Unix code owne