CVE-2017-2626

It was discovered that libICE before 1.0.9-8 used a weak entropy to generate keys. A local attacker could potentially use this flaw for session hijacking using the information available from the process list.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.2 MEDIUM
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
freedesktoplibice
𝑥
≤ 1.0.9
redhatenterprise_linux_desktop
7.0
redhatenterprise_linux_server
7.0
redhatenterprise_linux_server_aus
7.4
redhatenterprise_linux_server_eus
7.4
redhatenterprise_linux_server_eus
7.5
redhatenterprise_linux_workstation
7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libice
bookworm
2:1.0.10-1
fixed
bullseye
2:1.0.10-1
fixed
sid
2:1.1.1-1
fixed
trixie
2:1.1.1-1
fixed
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libice
artful
not-affected
bionic
Fixed 2:1.0.9-2ubuntu0.18.04.1
released
cosmic
not-affected
disco
not-affected
eoan
not-affected
focal
not-affected
groovy
not-affected
hirsute
not-affected
impish
not-affected
jammy
not-affected
kinetic
not-affected
precise
ignored
trusty
dne
xenial
Fixed 2:1.0.9-1ubuntu0.16.04.1+esm1
released
yakkety
ignored
zesty
ignored
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libICE-devel
suse enterprise desktop 15
1.0.9-1.25
fixed
suse enterprise desktop 15 SP1
1.0.9-1.25
fixed
suse enterprise desktop 15 SP2
1.0.9-1.25
fixed
suse enterprise desktop 15 SP3
1.0.9-1.25
fixed
suse enterprise desktop 15 SP4
1.0.9-1.25
fixed
suse enterprise desktop 15 SP5
1.0.9-1.25
fixed
suse enterprise desktop 15 SP6
1.0.9-1.25
fixed
suse enterprise desktop 15 SP7
1.0.9-1.25
fixed
suse enterprise sap 15
1.0.9-1.25
fixed
suse enterprise sap 15 SP1
1.0.9-1.25
fixed
suse enterprise sap 15 SP2
1.0.9-1.25
fixed
suse enterprise sap 15 SP3
1.0.9-1.25
fixed
suse enterprise sap 15 SP4
1.0.9-1.25
fixed
suse enterprise sap 15 SP5
1.0.9-1.25
fixed
suse enterprise sap 15 SP6
1.0.9-1.25
fixed
suse enterprise sap 15 SP7
1.0.9-1.25
fixed
suse enterprise server 15
1.0.9-1.25
fixed
suse enterprise server 15 SP1
1.0.9-1.25
fixed
suse enterprise server 15 SP2
1.0.9-1.25
fixed
suse enterprise server 15 SP3
1.0.9-1.25
fixed
suse enterprise server 15 SP4
1.0.9-1.25
fixed
suse enterprise server 15 SP5
1.0.9-1.25
fixed
suse enterprise server 15 SP6
1.0.9-1.25
fixed
suse enterprise server 15 SP7
1.0.9-1.25
fixed
libICE6
suse enterprise desktop 15
1.0.9-1.25
fixed
suse enterprise desktop 15 SP1
1.0.9-1.25
fixed
suse enterprise desktop 15 SP2
1.0.9-1.25
fixed
suse enterprise desktop 15 SP3
1.0.9-1.25
fixed
suse enterprise desktop 15 SP4
1.0.9-1.25
fixed
suse enterprise desktop 15 SP5
1.0.9-1.25
fixed
suse enterprise desktop 15 SP6
1.0.9-1.25
fixed
suse enterprise desktop 15 SP7
1.0.9-1.25
fixed
suse enterprise sap 12 SP5
1.0.8-12.1
fixed
suse enterprise sap 15
1.0.9-1.25
fixed
suse enterprise sap 15 SP1
1.0.9-1.25
fixed
suse enterprise sap 15 SP2
1.0.9-1.25
fixed
suse enterprise sap 15 SP3
1.0.9-1.25
fixed
suse enterprise sap 15 SP4
1.0.9-1.25
fixed
suse enterprise sap 15 SP5
1.0.9-1.25
fixed
suse enterprise sap 15 SP6
1.0.9-1.25
fixed
suse enterprise sap 15 SP7
1.0.9-1.25
fixed
suse enterprise server 12 SP4
1.0.8-12.1
fixed
suse enterprise server 12 SP5
1.0.8-12.1
fixed
suse enterprise server 15
1.0.9-1.25
fixed
suse enterprise server 15 SP1
1.0.9-1.25
fixed
suse enterprise server 15 SP2
1.0.9-1.25
fixed
suse enterprise server 15 SP3
1.0.9-1.25
fixed
suse enterprise server 15 SP4
1.0.9-1.25
fixed
suse enterprise server 15 SP5
1.0.9-1.25
fixed
suse enterprise server 15 SP6
1.0.9-1.25
fixed
suse enterprise server 15 SP7
1.0.9-1.25
fixed
libICE6-32bit
suse enterprise sap 12 SP5
1.0.8-12.1
fixed
suse enterprise server 12 SP4
1.0.8-12.1
fixed
suse enterprise server 12 SP5
1.0.8-12.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
drm-utils
RHEL 7
0:2.4.74-1.el7
fixed
libICE
RHEL 7
0:1.0.9-9.el7
fixed
libICE-devel
RHEL 7
0:1.0.9-9.el7
fixed
libX11
RHEL 7
0:1.6.5-1.el7
fixed
libX11-common
RHEL 7
0:1.6.5-1.el7
fixed
libX11-devel
RHEL 7
0:1.6.5-1.el7
fixed
libXaw
RHEL 7
0:1.0.13-4.el7
fixed
libXaw-devel
RHEL 7
0:1.0.13-4.el7
fixed
libXcursor
RHEL 7
0:1.1.14-8.el7
fixed
libXcursor-devel
RHEL 7
0:1.1.14-8.el7
fixed
libXdmcp
RHEL 7
0:1.1.2-6.el7
fixed
libXdmcp-devel
RHEL 7
0:1.1.2-6.el7
fixed
libXfixes
RHEL 7
0:5.0.3-1.el7
fixed
libXfixes-devel
RHEL 7
0:5.0.3-1.el7
fixed
libXfont
RHEL 7
0:1.5.2-1.el7
fixed
libXfont-devel
RHEL 7
0:1.5.2-1.el7
fixed
libXfont2
RHEL 7
0:2.0.1-2.el7
fixed
libXfont2-devel
RHEL 7
0:2.0.1-2.el7
fixed
libXi
RHEL 7
0:1.7.9-1.el7
fixed
libXi-devel
RHEL 7
0:1.7.9-1.el7
fixed
libXpm
RHEL 7
0:3.5.12-1.el7
fixed
libXpm-devel
RHEL 7
0:3.5.12-1.el7
fixed
libXrandr
RHEL 7
0:1.5.1-2.el7
fixed
libXrandr-devel
RHEL 7
0:1.5.1-2.el7
fixed
libXrender
RHEL 7
0:0.9.10-1.el7
fixed
libXrender-devel
RHEL 7
0:0.9.10-1.el7
fixed
libXt
RHEL 7
0:1.1.5-3.el7
fixed
libXt-devel
RHEL 7
0:1.1.5-3.el7
fixed
libXtst
RHEL 7
0:1.2.3-1.el7
fixed
libXtst-devel
RHEL 7
0:1.2.3-1.el7
fixed
libXv
RHEL 7
0:1.0.11-1.el7
fixed
libXv-devel
RHEL 7
0:1.0.11-1.el7
fixed
libXvMC
RHEL 7
0:1.0.10-1.el7
fixed
libXvMC-devel
RHEL 7
0:1.0.10-1.el7
fixed
libXxf86vm
RHEL 7
0:1.1.4-1.el7
fixed
libXxf86vm-devel
RHEL 7
0:1.1.4-1.el7
fixed
libdrm
RHEL 7
0:2.4.74-1.el7
fixed
libdrm-devel
RHEL 7
0:2.4.74-1.el7
fixed
libepoxy
RHEL 7
0:1.3.1-1.el7
fixed
libepoxy-devel
RHEL 7
0:1.3.1-1.el7
fixed
libevdev
RHEL 7
0:1.5.6-1.el7
fixed
libevdev-devel
RHEL 7
0:1.5.6-1.el7
fixed
libevdev-utils
RHEL 7
0:1.5.6-1.el7
fixed
libfontenc
RHEL 7
0:1.1.3-3.el7
fixed
libfontenc-devel
RHEL 7
0:1.1.3-3.el7
fixed
libinput
RHEL 7
0:1.6.3-2.el7
fixed
libinput-devel
RHEL 7
0:1.6.3-2.el7
fixed
libvdpau
RHEL 7
0:1.1.1-3.el7
fixed
libvdpau-devel
RHEL 7
0:1.1.1-3.el7
fixed
libvdpau-docs
RHEL 7
0:1.1.1-3.el7
fixed
libwacom
RHEL 7
0:0.24-1.el7
fixed
libwacom-data
RHEL 7
0:0.24-1.el7
fixed
libwacom-devel
RHEL 7
0:0.24-1.el7
fixed
libxcb
RHEL 7
0:1.12-1.el7
fixed
libxcb-devel
RHEL 7
0:1.12-1.el7
fixed
libxcb-doc
RHEL 7
0:1.12-1.el7
fixed
libxkbcommon
RHEL 7
0:0.7.1-1.el7
fixed
libxkbcommon-devel
RHEL 7
0:0.7.1-1.el7
fixed
libxkbcommon-x11
RHEL 7
0:0.7.1-1.el7
fixed
libxkbcommon-x11-devel
RHEL 7
0:0.7.1-1.el7
fixed
libxkbfile
RHEL 7
0:1.0.9-3.el7
fixed
libxkbfile-devel
RHEL 7
0:1.0.9-3.el7
fixed
mesa-dri-drivers
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-filesystem
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libEGL
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libEGL-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libGL
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libGL-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libGLES
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libGLES-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libOSMesa
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libOSMesa-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libgbm
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libgbm-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libglapi
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libxatracker
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-libxatracker-devel
RHEL 7
0:17.0.1-6.20170307.el7
fixed
mesa-private-llvm
RHEL 7
0:3.9.1-3.el7
fixed
mesa-private-llvm-devel
RHEL 7
0:3.9.1-3.el7
fixed
mesa-vulkan-drivers
RHEL 7
0:17.0.1-6.20170307.el7
fixed
vulkan
RHEL 7
0:1.0.39.1-2.el7
fixed
vulkan-devel
RHEL 7
0:1.0.39.1-2.el7
fixed
vulkan-filesystem
RHEL 7
0:1.0.39.1-2.el7
fixed
xcb-proto
RHEL 7
0:1.12-2.el7
fixed
xkeyboard-config
RHEL 7
0:2.20-1.el7
fixed
xkeyboard-config-devel
RHEL 7
0:2.20-1.el7
fixed
xorg-x11-proto-devel
RHEL 7
0:7.7-20.el7
fixed