CVE-2008-0299

NameCVE-2008-0299
SourceCVE (at NVD; RH)
Descriptioncommon.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
NVD severitymedium (attack range: remote)
Debian Bugs460706
Debian/oldstablenot vulnerable.
Debian/stablenot vulnerable.
Debian/testingnot vulnerable.
Debian/unstablenot vulnerable.

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
paramiko (PTS)lenny1.7.4-0.1fixed
squeeze1.7.6-5fixed
wheezy, sid1.7.7.1-2fixed

The information above is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
paramikosource(unstable)1.6.4-1.1low460706

Notes

[etch] - paramiko <no-dsa> (Minor issue)
http://www.lag.net/pipermail/paramiko/2008-January/000599.html

Search for package or bug name: Reporting problems

Home - Testing Security Team - Debian Security - Imprint