CVE-2017-2626Insufficient Entropy in Libice

Severity
5.5MEDIUMNVD
CNA5.2
EPSS
0.1%
top 73.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateNov 28

Description

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

Also affects: Enterprise Linux 7.4, 7.5

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jqp9-hwjj-p328: It was discovered that libICE before 12022-05-14
CVEList
CVE-2017-2626: It was discovered that libICE before 12018-07-27
OSV
CVE-2017-2626: It was discovered that libICE before 12018-07-27

📋Vendor Advisories

3
Ubuntu
libICE vulnerability2022-11-28
Red Hat
libICE: weak entropy usage in session keys2017-02-28
Debian
CVE-2017-2626: libice - It was discovered that libICE before 1.0.9-8 used a weak entropy to generate key...2017

💬Community

2
Bugzilla
CVE-2017-2626 libICE: weak entropy usage in session keys [fedora-all]2017-03-01
Bugzilla
CVE-2017-2626 libICE: weak entropy usage in session keys2017-02-20
CVE-2017-2626 — Insufficient Entropy in Libice | cvebase