Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2008-0299

Опубликовано: 13 янв. 2008
Источник: redhat

Описание

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=428727Paramiko insecure use of RandomPool

Связанные уязвимости

ubuntu
почти 18 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

nvd
почти 18 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

debian
почти 18 лет назад

common.py in Paramiko 1.7.1 and earlier, when using threads or forked ...

CVSS3: 6.5
github
больше 3 лет назад

Paramiko Unsafe randomness usage may allow access to sensitive information