Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS13cW1tLXE2NWctMmhxcs2vew
Paramiko Unsafe randomness usage may allow access to sensitive information
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
Permalink: https://github.com/advisories/GHSA-wqmm-q65g-2hqrJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS13cW1tLXE2NWctMmhxcs2vew
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: about 2 years ago
Updated: 3 months ago
Identifiers: GHSA-wqmm-q65g-2hqr, CVE-2008-0299
References:
- https://nvd.nist.gov/vuln/detail/CVE-2008-0299
- https://bugzilla.redhat.com/show_bug.cgi?id=428727
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39749
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706
- http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch
- http://security.gentoo.org/glsa/glsa-200803-07.xml
- https://web.archive.org/web/20080205095439/http://secunia.com/advisories/28488
- https://web.archive.org/web/20080627172450/http://secunia.com/advisories/28510
- https://web.archive.org/web/20080628232710/http://secunia.com/advisories/29168
- https://web.archive.org/web/20080720033315/http://www.lag.net/pipermail/paramiko/2008-January/000599.html
- https://web.archive.org/web/20081012023428/http://www.securityfocus.com/bid/27307
- https://github.com/advisories/GHSA-wqmm-q65g-2hqr
Affected Packages
pypi:paramiko
Dependent packages: 712Dependent repositories: 30,613
Downloads: 55,093,690 last month
Affected Version Ranges: <= 1.7.1-2
Fixed in: 1.7.1-3
All affected versions: 1.3.1, 1.5.1, 1.5.2, 1.5.4, 1.6.1, 1.6.2, 1.6.3, 1.6.4
All unaffected versions: 1.7.1, 1.7.2, 1.7.4, 1.7.5, 1.7.6, 1.8.0, 1.8.1, 1.9.0, 1.10.0, 1.10.1, 1.10.2, 1.10.3, 1.10.4, 1.10.5, 1.10.6, 1.10.7, 1.11.0, 1.11.1, 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6, 1.12.0, 1.12.1, 1.12.2, 1.12.3, 1.12.4, 1.13.0, 1.13.1, 1.13.2, 1.13.3, 1.13.4, 1.14.0, 1.14.1, 1.14.2, 1.14.3, 1.15.0, 1.15.1, 1.15.2, 1.15.3, 1.15.4, 1.15.5, 1.16.0, 1.16.1, 1.16.2, 1.16.3, 1.17.0, 1.17.1, 1.17.2, 1.17.3, 1.17.4, 1.17.5, 1.17.6, 1.18.0, 1.18.1, 1.18.2, 1.18.3, 1.18.4, 1.18.5, 2.0.0, 2.0.1, 2.0.2, 2.0.3, 2.0.4, 2.0.5, 2.0.6, 2.0.7, 2.0.8, 2.0.9, 2.1.0, 2.1.1, 2.1.2, 2.1.3, 2.1.4, 2.1.5, 2.1.6, 2.2.0, 2.2.1, 2.2.2, 2.2.3, 2.2.4, 2.3.0, 2.3.1, 2.3.2, 2.3.3, 2.4.0, 2.4.1, 2.4.2, 2.4.3, 2.5.0, 2.5.1, 2.6.0, 2.7.0, 2.7.1, 2.7.2, 2.8.0, 2.8.1, 2.9.0, 2.9.1, 2.9.2, 2.9.3, 2.9.4, 2.9.5, 2.10.0, 2.10.1, 2.10.2, 2.10.3, 2.10.4, 2.10.5, 2.10.6, 2.11.0, 2.11.1, 2.12.0, 3.0.0, 3.1.0, 3.2.0, 3.3.0, 3.3.1, 3.4.0