Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2023-48795

Medium priority

Some fixes available 38 of 85

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation...

13 affected packages

dropbear, golang-go.crypto, snapd, lxd, libssh...

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dropbear Needs evaluation Fixed Fixed Fixed
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Needs evaluation
snapd Not affected Not affected Not affected Not affected
lxd Not in release Not in release Not affected Fixed
libssh Not affected Fixed Fixed Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored
libssh2 Not affected Not affected Not affected Not affected
openssh Fixed Fixed Fixed Fixed
paramiko Fixed Fixed Fixed Needs evaluation
putty Needs evaluation Needs evaluation Needs evaluation Needs evaluation
proftpd-dfsg Not affected Not affected Fixed Needs evaluation
python-asyncssh Fixed Fixed Fixed Ignored
filezilla Fixed Fixed Fixed Not affected
Show all 13 packages Show less packages

CVE-2022-24302

Medium priority

Some fixes available 11 of 12

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

1 affected package

paramiko

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-7750

High priority
Fixed

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether...

1 affected package

paramiko

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko
Show less packages

CVE-2018-1000805

Medium priority
Fixed

Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.

1 affected package

paramiko

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko Fixed
Show less packages

CVE-2008-0299

Low priority
Ignored

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

1 affected package

paramiko

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko
Show less packages