Lucene search

K
ubuntucveUbuntu.comUB:CVE-2008-0299
HistoryJan 16, 2008 - 12:00 a.m.

CVE-2008-0299

2008-01-1600:00:00
ubuntu.com
ubuntu.com
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.007

Percentile

80.2%

common.py in Paramiko 1.7.1 and earlier, when using threads or forked
processes, does not properly use RandomPool, which allows one session to
obtain sensitive information from another session by predicting the state
of the pool.

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

EPSS

0.007

Percentile

80.2%