Insufficient Entropy in xcmsdb - CVE-2017-2626

 

Insufficient Entropy in xcmsdb - CVE-2017-2626

Published: July 27, 2018 / Updated: July 28, 2020


Vulnerability identifier: #VU32017
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2626
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.


Affected software

xcmsdb
cflinuxfs3
Gentoo Linux
Ubuntu
Fedora
libice (Alpine package)
libice6 (Ubuntu package)
libice-dev (Ubuntu package)
libICE

How to mitigate CVE-2017-2626

Install update from vendor's website.

xcmsdb - update to 1.0.9
libice (Alpine package) - update to 1.0.10-r0
libice6 (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
libice-dev (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 2:1.0.9-2ubuntu0.18.04.1
cflinuxfs3 - update to 0.341.0
libICE - addressed in versions 1.0.9-8.fc24, 1.0.9-8.fc25, 1.0.9-8.fc26

External References

Related Security Bulletins