CVE-2017-2625
published 2018-07-27CVE-2017-2625: It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could…
PriorityP422medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.53%
41.5th percentile
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libxdmcp | < libxdmcp 1:1.1.2-2 (bookworm) | libxdmcp 1:1.1.2-2 (bookworm) |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
| x.org | libxdmcp | < 1.1.2 | 1.1.2 |
| xorg | libxdmcp | — | — |
| xorg | libxdmcp | >= 0 < 1:1.1.2-2 | 1:1.1.2-2 |
| xorg | libxdmcp | >= 0 < 1:1.1.2-2 | 1:1.1.2-2 |
| xorg | libxdmcp | >= 0 < 1:1.1.2-2 | 1:1.1.2-2 |
| xorg | libxdmcp | >= 0 < 1:1.1.2-2 | 1:1.1.2-2 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libXdmcp vulnerability
vendor_ubuntu·2022-10-19
CVE-2017-2625 libXdmcp vulnerability
Title: libXdmcp vulnerability
Summary: libXdmcp could be made to expose sensitive information.
It was discovered that libXdmcp was generating weak session keys.
A local attacker could possibly use this issue to perform a brute
force attack and obtain another user's key.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libXdmcp: weak entropy usage for session keys
vendor_redhat·2017-02-28·CVSS 6.5
CVE-2017-2625 [MEDIUM] CWE-331 libXdmcp: weak entropy usage for session keys
libXdmcp: weak entropy usage for session keys
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
It was discovered that libXdmcp used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
Statement: Red Hat Product Security has rated this issue as having Moderate security impact. This issue is not currently planned to be addressed in future updates. For additional information, refe
Debian
CVE-2017-2625: libxdmcp - It was discovered that libXdmcp before 1.1.2 including used weak entropy to gene...
vendor_debian·2017·CVSS 6.5
CVE-2017-2625 [MEDIUM] CVE-2017-2625: libxdmcp - It was discovered that libXdmcp before 1.1.2 including used weak entropy to gene...
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
Scope: local
bookworm: resolved (fixed in 1:1.1.2-2)
bullseye: resolved (fixed in 1:1.1.2-2)
forky: resolved (fixed in 1:1.1.2-2)
sid: resolved (fixed in 1:1.1.2-2)
trixie: resolved (fixed in 1:1.1.2-2)
GHSA
GHSA-cvmx-9h9q-8hmw: It was discovered that libXdmcp before 1
ghsa_unreviewed·2022-05-13
CVE-2017-2625 [MEDIUM] CWE-331 GHSA-cvmx-9h9q-8hmw: It was discovered that libXdmcp before 1
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
OSV
CVE-2017-2625: It was discovered that libXdmcp before 1
osv·2018-07-27·CVSS 5.5
CVE-2017-2625 [MEDIUM] CVE-2017-2625: It was discovered that libXdmcp before 1
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-18869 nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js
bugzilla·2018-08-02·CVSS 2.5
CVE-2017-18869 [LOW] CVE-2017-18869 nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js
CVE-2017-18869 nodejs-chownr: TOCTOU vulnerability in `chownr` function in chownr.js
Affected versions of chownr are vulnerable to Time of Check Time of Use (TOCTOU). It does not dereference symbolic links and changes the owner of the link.
Upstream bug:
https://github.com/isaacs/chownr/issues/14
Upstream patch:
https://github.com/simevo/chownr/commit/0307bb7520c856f3e586815959141103ed7590c4
References:
https://snyk.io/vuln/npm:chownr:20180731
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=863985#10
Discussion:
This issue has been addressed in the following products:
Red Hat Software Collections for Red Hat Enterprise Linux 7
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
Via RHSA-2020:2625 h
Bugzilla
CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all]
bugzilla·2017-03-01·CVSS 6.5
CVE-2017-2625 [MEDIUM] CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all]
CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
Bugzilla
CVE-2017-2625 libXdmcp: weak entropy usage for session keys
bugzilla·2017-02-20·CVSS 6.5
CVE-2017-2625 [MEDIUM] CVE-2017-2625 libXdmcp: weak entropy usage for session keys
CVE-2017-2625 libXdmcp: weak entropy usage for session keys
The following flaw was reported in libXdmcp:
Summary and Impact
XDM uses weak entropy to generate the session keys on non-BSD systems:
void
XdmcpGenerateKey (XdmAuthKeyPtr key)
{
#ifndef HAVE_ARC4RANDOM_BUF
long lowbits, highbits;
srandom ((int)getpid() ^ time((Time_t *)0));
lowbits = random ();
highbits = random ();
getbits (lowbits, key->data);
getbits (highbits, key->data + 4);
#else
arc4random_buf(key->data, 8);
#endif
}
On multi user systems it might possible to check the PID of the process and how long it is running to get an estimate of these values, which could allow an attacker to attach to the session of a different user.
Discussion:
Acknowledgments:
Name: Eric Sesterhenn (X41 D-Sec GmbH)
---
Adjusted CVSS to
Bugzilla
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
bugzilla·2011-11-04·CVSS 5.0
CVE-2009-2625 [MEDIUM] CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
CVE-2009-2625 OpenJDK: XML parsing Denial-Of-Service (6845701) [epel-5]
epel-5 tracking bug for centerim: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
According to http://www.centerim.org/index.php/Main_Page, centerim 4.22.10 fixes this flaw. Current EPEL6 and >=F15 have this version already, so only F14 and EPEL5 are vulnerable.
---
Hi Lubo,
Have you had a chance to review this BZ? If I can be of assistance feel free to let me know what you need done. Thanks.
JT
---
Fedora EPEL 5 changed to end-of-life (EOL) status on 2017-03-31. Fedora EPEL 5
is no longer maintained, which means that it will not receive
http://www.securityfocus.com/bid/96480http://www.securitytracker.com/id/1037919https://access.redhat.com/errata/RHSA-2017:1865https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2625https://cgit.freedesktop.org/xorg/lib/libXdmcp/commit/?id=0554324ec6bbc2071f5d1f8ad211a1643e29eb1fhttps://lists.debian.org/debian-lts-announce/2019/11/msg00024.htmlhttps://security.gentoo.org/glsa/201704-03https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/http://www.securityfocus.com/bid/96480http://www.securitytracker.com/id/1037919https://access.redhat.com/errata/RHSA-2017:1865https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2625https://cgit.freedesktop.org/xorg/lib/libXdmcp/commit/?id=0554324ec6bbc2071f5d1f8ad211a1643e29eb1fhttps://lists.debian.org/debian-lts-announce/2019/11/msg00024.htmlhttps://security.gentoo.org/glsa/201704-03https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/
2018-07-27
Published