Lucene search

K
cveMitreCVE-2008-0299
HistoryJan 16, 2008 - 11:00 p.m.

CVE-2008-0299

2008-01-1623:00:00
mitre
web.nvd.nist.gov
34
cve-2008-0299
paramiko
information security
vulnerability
randompool

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0.007

Percentile

80.2%

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

Affected configurations

Nvd
Node
python_software_foundationparamikoMatch1.7.1
VendorProductVersionCPE
python_software_foundationparamiko1.7.1cpe:2.3:a:python_software_foundation:paramiko:1.7.1:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

5.7

Confidence

Low

EPSS

0.007

Percentile

80.2%