Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2008-0299
Description:common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
Test IDs: 1.3.6.1.4.1.25623.1.0.60510   1.3.6.1.4.1.25623.1.0.860222   1.3.6.1.4.1.25623.1.0.860479  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2008-0299
BugTraq ID: 27307
http://www.securityfocus.com/bid/27307
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00529.html
https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00594.html
http://security.gentoo.org/glsa/glsa-200803-07.xml
http://people.debian.org/~nion/nmu-diff/paramiko-1.6.4-1_1.6.4-1.1.patch
http://www.lag.net/pipermail/paramiko/2008-January/000599.html
http://secunia.com/advisories/28488
http://secunia.com/advisories/28510
http://secunia.com/advisories/29168
XForce ISS Database: paramiko-randompool-info-disclosure(39749)
https://exchange.xforce.ibmcloud.com/vulnerabilities/39749




© 1998-2025 E-Soft Inc. All rights reserved.