OESA-2021-1069
Dashboard / Vulnerabilities / OESA-2021-1069
Summary: python-paramiko security update
Details: Paramiko is a combination of the Esperanto words for "paranoid" and "friend". It is a module for Python 2.7/3.4+ that implements the SSH2 protocol for secure (encrypted and authenticated) connections to remote machines. Security Fix(es): Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.(CVE-2018-1000805)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1069, https://nvd.nist.gov/vuln/detail/CVE-2018-1000805
Affected packages
Package
Name: python-paramiko
Purl: pkg:rpm/openEuler/python-paramiko&distro=openEuler-20.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
