Lucene search

K
redhatcveRedhat.comRH:CVE-2017-2625
HistoryMar 01, 2017 - 12:18 a.m.

CVE-2017-2625

2017-03-0100:18:14
redhat.com
access.redhat.com
12

0.0004 Low

EPSS

Percentile

5.1%

It was discovered that libXdmcp used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users’ sessions.