Candidate: CVE-2017-2625 PublicDate: 2018-07-27 18:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2625 https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/ http://openwall.com/lists/oss-security/2017/03/01/1 Description: It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions. Ubuntu-Description: Notes: tyhicks> 1.1.2 and lower are affected Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=856399 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [5.5 MEDIUM] Patches_libxdmcp: upstream: https://cgit.freedesktop.org/xorg/lib/libXdmcp/commit/?id=0554324ec6bbc2071f5d1f8ad211a1643e29eb1f upstream: https://cgit.freedesktop.org/xorg/lib/libXdmcp/commit/?id=6d1aee0310001eca8f6ded9814a2a70b3a774896 upstream_libxdmcp: released (1:1.1.2-2) precise_libxdmcp: ignored (reached end-of-life) precise/esm_libxdmcp: ignored (end of ESM support, was needed) trusty_libxdmcp: ignored (reached end-of-life) trusty/esm_libxdmcp: needed vivid/stable-phone-overlay_libxdmcp: ignored (reached end-of-life) vivid/ubuntu-core_libxdmcp: DNE xenial_libxdmcp: ignored (end of standard support, was needed) esm-infra/xenial_libxdmcp: needed yakkety_libxdmcp: ignored (reached end-of-life) zesty_libxdmcp: ignored (reached end-of-life) artful_libxdmcp: ignored (reached end-of-life) bionic_libxdmcp: released (1:1.1.2-3) cosmic_libxdmcp: ignored (reached end-of-life) disco_libxdmcp: released (1:1.1.2-3) eoan_libxdmcp: released (1:1.1.2-3) focal_libxdmcp: released (1:1.1.2-3) groovy_libxdmcp: released (1:1.1.2-3) hirsute_libxdmcp: released (1:1.1.2-3) impish_libxdmcp: released (1:1.1.2-3) jammy_libxdmcp: released (1:1.1.2-3) devel_libxdmcp: released (1:1.1.2-3)