Vulnerabilities > CVE-2008-0299 - Unspecified vulnerability in Python Software Foundation Paramiko 1.7.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN python-software-foundation
nessus
Summary
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family Fedora Local Security Checks NASL id FEDORA_2008-0644.NASL description Apply patch to fix recently discovered security problem. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 29987 published 2008-01-16 reporter This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/29987 title Fedora 8 : python-paramiko-1.7.1-3.fc8 (2008-0644) NASL family Fedora Local Security Checks NASL id FEDORA_2008-0722.NASL description Apply patch to fix recently discovered security problem. Note that Tenable Network Security has extracted the preceding description block directly from the Fedora security advisory. Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues. last seen 2020-06-01 modified 2020-06-02 plugin id 29989 published 2008-01-16 reporter This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/29989 title Fedora 7 : python-paramiko-1.7.1-3.fc7 (2008-0722) NASL family Gentoo Local Security Checks NASL id GENTOO_GLSA-200803-07.NASL description The remote host is affected by the vulnerability described in GLSA-200803-07 (Paramiko: Information disclosure) Dwayne C. Litzenberger reported that the file last seen 2020-06-01 modified 2020-06-02 plugin id 31382 published 2008-03-07 reporter This script is Copyright (C) 2008-2019 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/31382 title GLSA-200803-07 : Paramiko: Information disclosure
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706
- http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch
- http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch
- http://secunia.com/advisories/28488
- http://secunia.com/advisories/28488
- http://secunia.com/advisories/28510
- http://secunia.com/advisories/28510
- http://secunia.com/advisories/29168
- http://secunia.com/advisories/29168
- http://security.gentoo.org/glsa/glsa-200803-07.xml
- http://security.gentoo.org/glsa/glsa-200803-07.xml
- http://www.lag.net/pipermail/paramiko/2008-January/000599.html
- http://www.lag.net/pipermail/paramiko/2008-January/000599.html
- http://www.securityfocus.com/bid/27307
- http://www.securityfocus.com/bid/27307
- https://bugzilla.redhat.com/show_bug.cgi?id=428727
- https://bugzilla.redhat.com/show_bug.cgi?id=428727
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39749
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39749
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html
- https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html