Improper access control in Paramiko - CVE-2018-1000805

 

Improper access control in Paramiko - CVE-2018-1000805

Published: October 24, 2018 / Updated: October 29, 2018


Vulnerability identifier: #VU15559
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000805
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper access control in SSH server. A remote unauthenticated attacker can bypass access controls via unspecified vectors and execute arbitrary code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Paramiko
Amazon Linux AMI
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
SUSE Enterprise Storage
Red Hat Enterprise Linux EUS Compute Node
Fedora
SUSE Linux Enterprise Storage
Red Hat Enterprise Linux for Power
Opensuse
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise Server
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Module for Python2
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Basesystem
openSUSE Leap
openEuler
PowerStore 9000X
PowerStore 7000X
PowerStore 5000X
PowerStore 3000X
PowerStore 1000X
PowerStoreX OS
py-paramiko (Alpine package)
python-paramiko
python2-paramiko
python-paramiko-help
python3-paramiko
python-paramiko-doc
Red Hat Virtualization
Red Hat Virtualization Host
PowerStore T
Data Computing Appliance (DCA)
IBM Netezza Analytics

How to mitigate CVE-2018-1000805

Install update from vendor's website.

py-paramiko (Alpine package) - addressed in versions 2.1.6-r0, 2.4.2-r0
python-paramiko - addressed in versions 2.1.1-0.9.el7, 2.3.3-1.fc27, 2.4.2-1.fc28, 2.4.2-1.fc29
python2-paramiko - update to 2.4.1-8
python-paramiko-help - update to 2.4.1-8
python3-paramiko - update to 2.4.1-8
python-paramiko - update to 2.4.1-8
python2-paramiko - update to 2.4.3-150100.6.15.1
python3-paramiko - update to 2.4.3-150100.6.15.1
python-paramiko-doc - update to 2.4.3-150100.6.15.1
PowerStoreX OS - update to 3.2.1.6-2476179
PowerStore T - update to 3.5.0.1-2083289
Data Computing Appliance (DCA) - update to 3.5.2.0
IBM Netezza Analytics - update to 11.2.29

External References

Related Security Bulletins