PublicDateAtUSN: 2018-10-08 Candidate: CVE-2018-1000805 PublicDate: 2018-10-08 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000805 https://ubuntu.com/security/notices/USN-3796-1 https://ubuntu.com/security/notices/USN-3796-2 https://ubuntu.com/security/notices/USN-3796-3 Description: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. Ubuntu-Description: Notes: ebarretto> with this issue, they decided to stop supporting versions 1.x mdeslaur> this issue is in the server code, not the client code Bugs: https://github.com/paramiko/paramiko/issues/1283 Priority: medium Discovered-by: Daniel Hoffman Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_paramiko: upstream: https://github.com/paramiko/paramiko/commit/56c96a659658acdbb873aef8809a7b508434dcce upstream_paramiko: released (2.4.2) precise/esm_paramiko: released (1.7.7.1-2ubuntu1.2) trusty_paramiko: released (1.10.1-1git1ubuntu0.2) trusty/esm_paramiko: released (1.10.1-1git1ubuntu0.2) xenial_paramiko: released (1.16.0-1ubuntu0.2) esm-infra/xenial_paramiko: released (1.16.0-1ubuntu0.2) bionic_paramiko: released (2.0.0-1ubuntu1.1) cosmic_paramiko: released (2.4.1-0ubuntu3.1) devel_paramiko: released (2.4.1-0ubuntu3.1)