Lucene search

K
osvGoogleOSV:USN-5351-2
HistoryMar 30, 2022 - 7:33 a.m.

paramiko vulnerability

2022-03-3007:33:49
Google
osv.dev
7
usn-5351-1
paramiko
vulnerability
permissions
private keys
ubuntu 16.04 esm

AI Score

6.7

Confidence

Low

EPSS

0.003

Percentile

65.5%

USN-5351-1 fixed a vulnerability in Paramiko. This update provides
the corresponding update for Ubuntu 16.04 ESM.

Original advisory details:

Jan Schejbal discovered that Paramiko incorrectly handled permissions when
writing private key files. A local attacker could possibly use this issue
to gain access to private keys.