CVE Vulnerabilities

CVE-2008-0299

Published: Jan 16, 2008 | Modified: Aug 08, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Affected Software

Name Vendor Start Version End Version
Paramiko Python_software_foundation 1.7.1 (including) 1.7.1 (including)
Paramiko Ubuntu dapper *
Paramiko Ubuntu edgy *
Paramiko Ubuntu feisty *
Paramiko Ubuntu gutsy *
Paramiko Ubuntu hardy *
Paramiko Ubuntu upstream *

References