Key management errors in xcmsdb - CVE-2017-2625

 

Key management errors in xcmsdb - CVE-2017-2625

Published: July 27, 2018 / Updated: July 28, 2020


Vulnerability identifier: #VU32096
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-2625
CWE-ID: CWE-320
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local authenticated user to gain access to sensitive information.

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.


Affected software

xcmsdb
Tanzu Greenplum for Kubernetes
Gentoo Linux
Ubuntu
Fedora
libxdmcp (Alpine package)
libxdmcp6 (Ubuntu package)
libXdmcp
VMware Tanzu Operations Manager

How to mitigate CVE-2017-2625

Install update from vendor's website.

xcmsdb - update to 1.1.2
libxdmcp (Alpine package) - update to 1.1.2-r3
libxdmcp6 (Ubuntu package) - update to Ubuntu Pro (Infra-only)
libXdmcp - addressed in versions 1.1.2-5.fc24, 1.1.2-5.fc25, 1.1.2-5.fc26
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39

External References

Related Security Bulletins