CVE-2008-0299
Summary
| CVE | CVE-2008-0299 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-01-16 23:00:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool. |
Risk And Classification
Primary CVSS: v2.0 4.3 from [email protected]
AV:N/AC:M/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:M/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Python Software Foundation | Paramiko | 1.7.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [paramiko] [MERGE] insecure use of RandomPool | af854a3a-2127-422b-91ae-364da2661108 | www.lag.net | |
| paramiko Random Number Generator Weakness | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Fedora update for python-paramiko - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| #460706 - python-paramiko: CVE-2008-0299 insecure use of RandomPool - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| paramiko "RandomPool" Insecure Random Number Generator - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| [SECURITY] Fedora 7 Update: python-paramiko-1.7.1-3.fc7 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 428727 – (CVE-2008-0299) CVE-2008-0299 Paramiko insecure use of RandomPool | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Paramiko: Information disclosure — Gentoo Linux Documentation | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| [SECURITY] Fedora 8 Update: python-paramiko-1.7.1-3.fc8 | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | people.debian.org | Exploit |
| Gentoo update for paramiko - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997214 Python (Pip) Security Update for paramiko (GHSA-wqmm-q65g-2hqr)