RSS   Vulnerabilities for 'Libxdmcp'   RSS

2018-07-27
 
CVE-2017-2625

CWE-320
 

 
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

 

 >>> Vendor: X.org 34 Products
Xfree86
X11r6
X11
Xterm
XDM
X.org
X11r7
Emu-linux-x87-xlibs
Xf86dga
Xinit
Xload
Xorg-server
Libx11
Libxfont
X window system
Xserver
X font server
Xinput
Tog-cup
EVI
Mit-shm
X server
X.org x11
Libxfixes
Libxi
Libxinerama
Libxrandr
Libxrender
Libxv
Libxvmc
Libxtst
X.org-server
X.xorg-server
Libxdmcp


Copyright 2024, cxsecurity.com

 

Back to Top