Key management errors in xcmsdb - CVE-2017-2625
Published: July 27, 2018 / Updated: July 28, 2020
Vulnerability details
The vulnerability allows a local authenticated user to gain access to sensitive information.
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
Affected software
Tanzu Greenplum for Kubernetes
Gentoo Linux
Ubuntu
Fedora
libxdmcp (Alpine package)
libxdmcp6 (Ubuntu package)
libXdmcp
VMware Tanzu Operations Manager
How to mitigate CVE-2017-2625
libxdmcp (Alpine package) - update to 1.1.2-r3
libxdmcp6 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libXdmcp - addressed in versions 1.1.2-5.fc24, 1.1.2-5.fc25, 1.1.2-5.fc26
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
External References
- http://www.securityfocus.com/bid/96480
- http://www.securitytracker.com/id/1037919
- https://access.redhat.com/errata/RHSA-2017:1865
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2625
- https://cgit.freedesktop.org/xorg/lib/libXdmcp/commit/?id=0554324ec6bbc2071f5d1f8ad211a1643e29eb1f
- https://lists.debian.org/debian-lts-announce/2019/11/msg00024.html
- https://security.gentoo.org/glsa/201704-03
- https://www.x41-dsec.de/lab/advisories/x41-2017-001-xorg/