CVE Vulnerabilities

CVE-2008-0299

Published: Jan 16, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Affected Software

NameVendorStart VersionEnd Version
ParamikoPython_software_foundation1.7.1 (including)1.7.1 (including)
ParamikoUbuntudapper*
ParamikoUbuntuedgy*
ParamikoUbuntufeisty*
ParamikoUbuntugutsy*
ParamikoUbuntuhardy*
ParamikoUbuntuupstream*

References