It has been found, that libxdmcp, an X11 Display Manager Control Protocol library, uses weak entropy to generate keys. . Package : libxdmcp Version : 1:1.1.1-1+deb8u1 CVE ID : CVE-2017-2625 It has been found, that libxdmcp, an X11 Display Manager Control Protocol library, uses weak entropy to generate keys. Using arc4random_buf() from libbsd should avoid this flaw. For Debian 8 "Jessie", this problem has been fixed in version 1:1.1.1-1+deb8u1. We recommend that you upgrade your libxdmcp packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Address the weak entropy issue in libxdmcp for improved key generation security. Important notice for Debian 8 users. It's advisable to upgrade now!. Libxdmcp Update, Debian LTS, Key Generation Flaw, Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2017-2625. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-09f65e5e00 2017-04-01 16:46:19.651051 -------------------------------------------------------------------------------- Name : libXdmcp Product : Fedora 26 Version : 1.1.2 Release : 5.fc26 URL : https://www.x.org/wiki/ Summary : X Display Manager Control Protocol library Description : X Display Manager Control Protocol library. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2625 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1427716 - CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427716 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXdmcp' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Security fix for CVE-2017-2625. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-bcb1999e65 2017-03-05 17:28:15.511158 -------------------------------------------------------------------------------- Name : libXdmcp Product : Fedora 24 Version : 1.1.2 Release : 5.fc24 URL : https://www.x.org/wiki/ Summary : X Display Manager Control Protocol library Description : X Display Manager Control Protocol library. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-2625 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1427716 - CVE-2017-2625 libXdmcp: weak entropy usage for session keys [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427716 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libXdmcp' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.