Back to search
CVE-2008-0299
Published: Jan 16, 2008
Modified: Aug 7, 2024
PUBLISHED
Description
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugzilla.redhat.com/show_bug.cgi?id=428727
x_refsource_CONFIRM
FEDORA-2008-0644
vendor-advisory
x_refsource_FEDORA
paramiko-randompool-info-disclosure(39749)
vdb-entry
x_refsource_XF
http://www.lag.net/pipermail/paramiko/2008-January/000599.html
x_refsource_MISC
GLSA-200803-07
vendor-advisory
x_refsource_GENTOO
28510
third-party-advisory
x_refsource_SECUNIA
29168
third-party-advisory
x_refsource_SECUNIA
28488
third-party-advisory
x_refsource_SECUNIA
27307
vdb-entry
x_refsource_BID
FEDORA-2008-0722
vendor-advisory
x_refsource_FEDORA
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now