UBUNTU-CVE-2017-2626
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-2626
UBUNTU-CVE-2017-2626
Summary:
Details: It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
References: https://ubuntu.com/security/CVE-2017-2626, https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/, http://openwall.com/lists/oss-security/2017/03/01/1, https://cgit.freedesktop.org/xorg/lib/libICE/commit/?id=ff5e59f32255913bb1cdf51441b98c9107ae165b, https://ubuntu.com/security/notices/USN-5744-1, https://www.cve.org/CVERecord?id=CVE-2017-2626
Affected packages
Package
Name: libice
Purl: pkg:deb/ubuntu/libice@2:1.0.9-1ubuntu0.16.04.1+esm1?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
