python-paramiko-2.1.1-4.el7

エラータID: AXSA:2018-2636:01

リリース日: 
2018/03/28 Wednesday - 20:48
題名: 
python-paramiko-2.1.1-4.el7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

The python-paramiko package provides a Python module that implements the SSH2
protocol for encrypted and authenticated connections to remote machines. Unlike
SSL, the SSH2 protocol does not require hierarchical certificates signed by a
powerful central authority. The protocol also includes the ability to open
arbitrary channels to remote services across an encrypted tunnel.

Security Fix(es):

* python-paramiko: Authentication bypass in transport.py (CVE-2018-7750)

For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.

Bug Fix(es):

* python-paramiko has been using the python2-pyasn1 package, but did not depend
on it. With new versions of python2-cryptography, python2-pyasn1 was not getting
installed and this caused python-paramiko to malfunction. This bug was fixed by
making python-paramiko depend on python2-pyasn1 explicitly. (BZ#1559133)

CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x
before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x
before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether
authentication is completed before processing other requests, as demonstrated by
channel-open. A customized SSH client can simply skip the authentication step.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. python-paramiko-2.1.1-4.el7.src.rpm
    MD5: b0711610010e8a5e62a25b960678ed70
    SHA-256: f89ba062cd6b4edd867f98187d8e3bbcbf79a0ad668e71668aee911e4477f58e
    Size: 267.29 kB

Asianux Server 7 for x86_64
  1. python-paramiko-2.1.1-4.el7.noarch.rpm
    MD5: 3111d959283f7c274073348eac6d6fa2
    SHA-256: 8aabe6f2e45dc5188e4d32eeefaa16e5801659046727b371f323dca77fd5c44e
    Size: 267.24 kB