Improper access control in Paramiko - CVE-2018-1000805
Published: October 24, 2018 / Updated: October 29, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper access control in SSH server. A remote unauthenticated attacker can bypass access controls via unspecified vectors and execute arbitrary code.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Red Hat Enterprise Linux EUS Compute Node
Fedora
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power
Opensuse
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
py-paramiko (Alpine package)
python-paramiko
python2-paramiko
python-paramiko-help
python3-paramiko
python-paramiko-doc
Red Hat Virtualization
Red Hat Virtualization Host
PowerStore T
Data Computing Appliance (DCA)
IBM Netezza Analytics
How to mitigate CVE-2018-1000805
python-paramiko - addressed in versions 2.1.1-0.9.el7, 2.3.3-1.fc27, 2.4.2-1.fc28, 2.4.2-1.fc29
python2-paramiko - update to 2.4.1-8
python-paramiko-help - update to 2.4.1-8
python3-paramiko - update to 2.4.1-8
python-paramiko - update to 2.4.1-8
python2-paramiko - update to 2.4.3-150100.6.15.1
python3-paramiko - update to 2.4.3-150100.6.15.1
python-paramiko-doc - update to 2.4.3-150100.6.15.1
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289
Data Computing Appliance (DCA) - update to 3.5.2.0
IBM Netezza Analytics - update to 11.2.29
External References
Related Security Bulletins
- Remote code execution in Paramiko
- Amazon Linux AMI update for python-paramiko
- Red Hat update for paramiko
- OpenSUSE Linux update for python-paramiko
- Red Hat update for python-paramiko
- Red Hat update for python-paramiko
- Improper access control in py-paramiko (Alpine package)
- SUSE update for python-paramiko
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- Multiple vulnerabilities in Dell PowerStore Family
- openEuler update for python-paramiko
- Fedora 28 update for python-paramiko
- Fedora 29 update for python-paramiko
- Fedora 27 update for python-paramiko
- Fedora EPEL 7 update for python-paramiko
- Multiple vulnerabilities in Dell PowerStore X
- Multiple vulnerabilities in IBM Netezza Analytics - NPS