Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2023-48795

Medium priority

Some fixes available 46 of 85

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation...

13 affected packages

dropbear, golang-go.crypto, snapd, lxd, libssh...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dropbear Needs evaluation Needs evaluation Fixed Fixed Fixed
golang-go.crypto Needs evaluation Needs evaluation Needs evaluation Ignored Ignored
snapd Not affected Not affected Not affected Not affected Not affected
lxd Not in release Not in release Not in release Not affected Fixed
libssh Not affected Not affected Fixed Fixed Not affected
openssh-ssh1 Ignored Ignored Ignored Ignored Ignored
libssh2 Not affected Not affected Not affected Not affected Not affected
openssh Fixed Fixed Fixed Fixed Fixed
paramiko Fixed Fixed Fixed Fixed Ignored
putty Not affected Needs evaluation Needs evaluation Ignored Ignored
proftpd-dfsg Needs evaluation Not affected Not affected Fixed Ignored
python-asyncssh Fixed Fixed Fixed Fixed Ignored
filezilla Fixed Fixed Fixed Fixed Not affected
Show all 13 packages Show less packages

CVE-2022-24302

Medium priority

Some fixes available 13 of 14

In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.

1 affected package

paramiko

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2018-1000805

Medium priority
Fixed

Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.

1 affected package

paramiko

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko Fixed
Show less packages

CVE-2018-7750

High priority
Fixed

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether...

1 affected package

paramiko

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko
Show less packages

CVE-2008-0299

Low priority
Ignored

common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.

1 affected package

paramiko

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
paramiko
Show less packages