CVE-2008-0299
Paramiko < 1.7.1-3 - Information Disclosure via RandomPool State Prediction
Title source: llmDescription
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
References (12)
Core 12
Core References
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=428727
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/39749
Exploit x_refsource_misc
http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch
Various Sources x_refsource_misc
http://www.lag.net/pipermail/paramiko/2008-January/000599.html
Third Party Advisory vendor-advisory
x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-07.xml
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28510
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/29168
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/28488
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/27307
Vendor Advisory vendor-advisory
x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html
Issue Tracking x_refsource_confirm
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=460706
Scores
EPSS
0.0162
EPSS Percentile
73.6%
Details
Status
published
Products (2)
pypi/paramiko
0 - 1.7.1-3PyPI
python_software_foundation/paramiko
1.7.1
Published
Jan 16, 2008
Tracked Since
Feb 18, 2026