Insufficient Entropy in xcmsdb - CVE-2017-2626
Published: July 27, 2018 / Updated: July 28, 2020
Vulnerability identifier: #VU32017
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2626
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
Affected software
xcmsdb
cflinuxfs3
Gentoo Linux
Ubuntu
Fedora
libice (Alpine package)
libice6 (Ubuntu package)
libice-dev (Ubuntu package)
libICE
cflinuxfs3
Gentoo Linux
Ubuntu
Fedora
libice (Alpine package)
libice6 (Ubuntu package)
libice-dev (Ubuntu package)
libICE
How to mitigate CVE-2017-2626
Install update from vendor's website.
xcmsdb - update to 1.0.9
libice (Alpine package) - update to 1.0.10-r0
libice6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
libice-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
cflinuxfs3 - update to 0.341.0
libICE - addressed in versions 1.0.9-8.fc24, 1.0.9-8.fc25, 1.0.9-8.fc26
libice (Alpine package) - update to 1.0.10-r0
libice6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
libice-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
cflinuxfs3 - update to 0.341.0
libICE - addressed in versions 1.0.9-8.fc24, 1.0.9-8.fc25, 1.0.9-8.fc26
External References
- http://www.openwall.com/lists/oss-security/2019/07/14/3
- http://www.securityfocus.com/bid/96480
- http://www.securitytracker.com/id/1037919
- https://access.redhat.com/errata/RHSA-2017:1865
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2626
- https://cgit.freedesktop.org/xorg/lib/libICE/commit/?id=ff5e59f32255913bb1cdf51441b98c9107ae165b
- https://lists.debian.org/debian-lts-announce/2019/11/msg00022.html
- https://security.gentoo.org/glsa/201704-03
- https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/