CVE-2008-0299
common.py in Paramiko 1.7.1 and earlier, when using threads or forked processes, does not properly use RandomPool, which allows one session to obtain sensitive information from another session by predicting the state of the pool.
- Affected products
- Paramiko
- Python Software Foundation Paramiko
- = 1.7.1
- CVSS 2.0
- 4.3 MEDIUM
- EPSS
- 1.6% (74th percentile)
- NVD status
- Modified
- Published
- 2008-01-16
CVE-2008-0299 at NVD
No indexed exploits for CVE-2008-0299 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2008-0299 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.