CVE-2017-2626

MEDIUM

libICE <1.0.9-8 - Info Disclosure

Title source: llm
STIX 2.1

Description

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

Scores

CVSS v3 5.2
EPSS 0.0010
EPSS Percentile 26.7%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L

Details

CWE
CWE-331
Status published
Products (7)
freedesktop/libice < 1.0.9
redhat/enterprise_linux_desktop 7.0
redhat/enterprise_linux_server 7.0
redhat/enterprise_linux_server_aus 7.4
redhat/enterprise_linux_server_eus 7.4
redhat/enterprise_linux_server_eus 7.5
redhat/enterprise_linux_workstation 7.0
Published Jul 27, 2018
Tracked Since Feb 18, 2026