CVE-2017-2625

ADVISORY - nist

Summary

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

EPSS Score: 0.00045 (0.134)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Key Management Errors

Insufficient Entropy

ADVISORY - redhat

Insufficient Entropy


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in