ZeroHour

CVE-2017-2626

CVSS 3.0
5.5 medium
EPSS
<1%p39
Published
()
Modified
Description

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

Vendors
freedesktopredhat
Products
libice, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux workstation
Weakness
CWE-331
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.