python-paramiko-2.1.1-4.el7
エラータID: AXSA:2018-2636:01
The python-paramiko package provides a Python module that implements the SSH2
protocol for encrypted and authenticated connections to remote machines. Unlike
SSL, the SSH2 protocol does not require hierarchical certificates signed by a
powerful central authority. The protocol also includes the ability to open
arbitrary channels to remote services across an encrypted tunnel.
Security Fix(es):
* python-paramiko: Authentication bypass in transport.py (CVE-2018-7750)
For more details about the security issue(s), including the impact, a CVSS
score, and other related information, refer to the CVE page(s) listed in the
References section.
Bug Fix(es):
* python-paramiko has been using the python2-pyasn1 package, but did not depend
on it. With new versions of python2-cryptography, python2-pyasn1 was not getting
installed and this caused python-paramiko to malfunction. This bug was fixed by
making python-paramiko depend on python2-pyasn1 explicitly. (BZ#1559133)
CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x
before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x
before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether
authentication is completed before processing other requests, as demonstrated by
channel-open. A customized SSH client can simply skip the authentication step.
Update packages.
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
N/A
SRPMS
- python-paramiko-2.1.1-4.el7.src.rpm
MD5: b0711610010e8a5e62a25b960678ed70
SHA-256: f89ba062cd6b4edd867f98187d8e3bbcbf79a0ad668e71668aee911e4477f58e
Size: 267.29 kB
Asianux Server 7 for x86_64
- python-paramiko-2.1.1-4.el7.noarch.rpm
MD5: 3111d959283f7c274073348eac6d6fa2
SHA-256: 8aabe6f2e45dc5188e4d32eeefaa16e5801659046727b371f323dca77fd5c44e
Size: 267.24 kB