Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0299

Опубликовано: 16 янв. 2008
Источник: nvd
CVSS2: 4.3
EPSS Низкий

Описание

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:python_software_foundation:paramiko:1.7.1:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01232
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 17 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

redhat
больше 17 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

debian
больше 17 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked ...

CVSS3: 6.5
github
больше 3 лет назад

Paramiko Unsafe randomness usage may allow access to sensitive information

EPSS

Процентиль: 78%
0.01232
Низкий

4.3 Medium

CVSS2

Дефекты

NVD-CWE-Other