ALPINE-CVE-2017-2625

Source
https://security.alpinelinux.org/vuln/CVE-2017-2625
Import Source
https://storage.googleapis.com/cve-osv-conversion/alpine/ALPINE-CVE-2017-2625.json
JSON Data
https://api.osv.dev/v1/vulns/ALPINE-CVE-2017-2625
Upstream
Published
2018-07-27T18:29:00.860Z
Modified
2025-12-03T22:42:03.594738Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.

References

Affected packages

Alpine:v3.10

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.11

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.12

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.13

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.14

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.15

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.16

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.17

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.18

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.19

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.20

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.21

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.22

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.23

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.6

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.7

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.8

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2

Alpine:v3.9

libxdmcp

Package

Name
libxdmcp
Purl
pkg:apk/alpine/libxdmcp?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.2-r3

Affected versions

1.*

1.0.2-r0
1.0.2-r1
1.0.3-r0
1.0.3-r1
1.0.3-r2
1.0.3-r3
1.1.0-r0
1.1.0-r1
1.1.0-r2
1.1.1-r0
1.1.2-r0
1.1.2-r1
1.1.2-r2