CVE Vulnerabilities

CVE-2017-2626

Insufficient Entropy

Published: Jul 27, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
5.2 LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

NameVendorStart VersionEnd Version
LibiceFreedesktop*1.0.9 (including)
Red Hat Enterprise Linux 7RedHatlibdrm-0:2.4.74-1.el7*
Red Hat Enterprise Linux 7RedHatlibepoxy-0:1.3.1-1.el7*
Red Hat Enterprise Linux 7RedHatlibevdev-0:1.5.6-1.el7*
Red Hat Enterprise Linux 7RedHatlibfontenc-0:1.1.3-3.el7*
Red Hat Enterprise Linux 7RedHatlibICE-0:1.0.9-9.el7*
Red Hat Enterprise Linux 7RedHatlibinput-0:1.6.3-2.el7*
Red Hat Enterprise Linux 7RedHatlibvdpau-0:1.1.1-3.el7*
Red Hat Enterprise Linux 7RedHatlibwacom-0:0.24-1.el7*
Red Hat Enterprise Linux 7RedHatlibX11-0:1.6.5-1.el7*
Red Hat Enterprise Linux 7RedHatlibXaw-0:1.0.13-4.el7*
Red Hat Enterprise Linux 7RedHatlibxcb-0:1.12-1.el7*
Red Hat Enterprise Linux 7RedHatlibXcursor-0:1.1.14-8.el7*
Red Hat Enterprise Linux 7RedHatlibXdmcp-0:1.1.2-6.el7*
Red Hat Enterprise Linux 7RedHatlibXfixes-0:5.0.3-1.el7*
Red Hat Enterprise Linux 7RedHatlibXfont-0:1.5.2-1.el7*
Red Hat Enterprise Linux 7RedHatlibXfont2-0:2.0.1-2.el7*
Red Hat Enterprise Linux 7RedHatlibXi-0:1.7.9-1.el7*
Red Hat Enterprise Linux 7RedHatlibxkbcommon-0:0.7.1-1.el7*
Red Hat Enterprise Linux 7RedHatlibxkbfile-0:1.0.9-3.el7*
Red Hat Enterprise Linux 7RedHatlibXpm-0:3.5.12-1.el7*
Red Hat Enterprise Linux 7RedHatlibXrandr-0:1.5.1-2.el7*
Red Hat Enterprise Linux 7RedHatlibXrender-0:0.9.10-1.el7*
Red Hat Enterprise Linux 7RedHatlibXt-0:1.1.5-3.el7*
Red Hat Enterprise Linux 7RedHatlibXtst-0:1.2.3-1.el7*
Red Hat Enterprise Linux 7RedHatlibXv-0:1.0.11-1.el7*
Red Hat Enterprise Linux 7RedHatlibXvMC-0:1.0.10-1.el7*
Red Hat Enterprise Linux 7RedHatlibXxf86vm-0:1.1.4-1.el7*
Red Hat Enterprise Linux 7RedHatmesa-0:17.0.1-6.20170307.el7*
Red Hat Enterprise Linux 7RedHatmesa-private-llvm-0:3.9.1-3.el7*
Red Hat Enterprise Linux 7RedHatvulkan-0:1.0.39.1-2.el7*
Red Hat Enterprise Linux 7RedHatxcb-proto-0:1.12-2.el7*
Red Hat Enterprise Linux 7RedHatxkeyboard-config-0:2.20-1.el7*
Red Hat Enterprise Linux 7RedHatxorg-x11-proto-devel-0:7.7-20.el7*
LibiceUbuntubionic*
LibiceUbuntuesm-infra/bionic*
LibiceUbuntuesm-infra/xenial*
LibiceUbuntuprecise*
LibiceUbuntutrusty*
LibiceUbuntuupstream*
LibiceUbuntuvivid/stable-phone-overlay*
LibiceUbuntuxenial*
LibiceUbuntuyakkety*
LibiceUbuntuzesty*

Potential Mitigations

References