Description
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
References (9)
Scores
CVSS v3
5.2
EPSS
0.0010
EPSS Percentile
26.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Details
CWE
CWE-331
Status
published
Products (7)
freedesktop/libice
< 1.0.9
redhat/enterprise_linux_desktop
7.0
redhat/enterprise_linux_server
7.0
redhat/enterprise_linux_server_aus
7.4
redhat/enterprise_linux_server_eus
7.4
redhat/enterprise_linux_server_eus
7.5
redhat/enterprise_linux_workstation
7.0
Published
Jul 27, 2018
Tracked Since
Feb 18, 2026