CVE Database · CVE-2017-2625
CVSS v3.1
N/A
EPSS
0.53%
Published
Jul 27, 2018
Modified
Nov 21, 2024
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
Weaknesses (CWE)
Affected Products (8)
References (16)