CVE-2018-1000805

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000805
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1000805.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000805
Aliases
Related
Published
2018-10-08T15:29:00Z
Modified
2024-10-12T03:19:31.570473Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.

References

Affected packages

Alpine:v3.11 / py3-paramiko

Package

Name
py3-paramiko
Purl
pkg:apk/alpine/py3-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0
2.4.1-r0

Alpine:v3.12 / py3-paramiko

Package

Name
py3-paramiko
Purl
pkg:apk/alpine/py3-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0
2.4.1-r0

Alpine:v3.13 / py3-paramiko

Package

Name
py3-paramiko
Purl
pkg:apk/alpine/py3-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0
2.4.1-r0

Alpine:v3.14 / py3-paramiko

Package

Name
py3-paramiko
Purl
pkg:apk/alpine/py3-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0
2.4.1-r0

Alpine:v3.6 / py-paramiko

Package

Name
py-paramiko
Purl
pkg:apk/alpine/py-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.6-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0

Alpine:v3.7 / py-paramiko

Package

Name
py-paramiko
Purl
pkg:apk/alpine/py-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0

Alpine:v3.8 / py-paramiko

Package

Name
py-paramiko
Purl
pkg:apk/alpine/py-paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-r0

Affected versions

1.*

1.7.7.1-r0
1.9.0-r0
1.10.1-r0
1.11.0-r0
1.12.0-r0
1.14.0-r0
1.14.1-r0
1.15.1-r0
1.15.2-r0
1.16.0-r0

2.*

2.0.1-r1
2.0.1-r2
2.0.2-r0
2.0.2-r1
2.0.2-r2
2.0.2-r3
2.1.2-r0
2.2.0-r0
2.2.1-r0
2.2.1-r1
2.3.1-r0
2.4.0-r0
2.4.1-r0

Debian:11 / paramiko

Package

Name
paramiko
Purl
pkg:deb/debian/paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / paramiko

Package

Name
paramiko
Purl
pkg:deb/debian/paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / paramiko

Package

Name
paramiko
Purl
pkg:deb/debian/paramiko?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.2-0.1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git

Affected ranges

Type
GIT
Repo
http://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
39a8804455fb23f09157341d3ba7db6d7ae6ee76
Last affected
c16fa4f2ad19908a47c63d8fa436a1178438c7e7
Type
GIT
Repo
https://github.com/paramiko/paramiko
Events

Affected versions

1.*

1.10.0
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.10.6
1.10.7
1.11.0
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.12.0
1.12.1
1.12.2
1.12.3
1.12.4
1.13.0
1.13.1
1.13.2
1.13.3
1.13.4
1.14.0
1.14.1
1.14.2
1.14.3
1.15.0
1.15.1
1.15.2
1.15.3
1.15.4
1.15.5
1.16.0
1.16.1
1.16.2
1.16.3
1.17.0
1.17.1
1.17.2
1.17.3
1.17.4
1.17.5
1.17.6
1.18.0
1.18.1
1.18.2
1.18.3
1.18.4
1.18.5
1.7.7.1
1.7.7.2
1.8.0
1.8.1
1.9.0

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.0.5
2.0.6
2.0.7
2.0.8
2.1.0
2.1.1
2.1.2
2.1.3
2.1.4
2.1.5
2.2.0
2.2.1
2.2.2
2.2.3

Other

initial-merge-from-ssh-done
py3-test-parity

release-1.*

release-1.7.4
release-1.7.5
release-1.7.6

v1.*

v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.10.5
v1.10.6
v1.10.7
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.11.4
v1.11.5
v1.11.6
v1.12.0
v1.12.1
v1.12.2
v1.12.3
v1.12.4
v1.13.0
v1.13.1
v1.13.2
v1.13.3
v1.13.4
v1.14.0
v1.14.1
v1.14.2
v1.14.3
v1.15.0
v1.15.1
v1.15.2
v1.15.3
v1.15.4
v1.15.5
v1.16.0
v1.16.1
v1.16.2
v1.16.3
v1.17.0
v1.17.1
v1.17.2
v1.17.3
v1.18.0
v1.18.1
v1.7.7.1
v1.7.7.2
v1.8.0
v1.8.1
v1.9.0

v2.*

v2.6.12
v2.6.12-rc2
v2.6.12-rc3
v2.6.12-rc4
v2.6.12-rc5
v2.6.12-rc6
v2.6.13
v2.6.13-rc1
v2.6.13-rc2
v2.6.13-rc3
v2.6.13-rc4
v2.6.13-rc5
v2.6.13-rc6
v2.6.13-rc7
v2.6.14
v2.6.14-rc1
v2.6.14-rc2
v2.6.14-rc3
v2.6.14-rc4
v2.6.14-rc5
v2.6.15
v2.6.15-rc1
v2.6.15-rc2
v2.6.15-rc3
v2.6.15-rc4
v2.6.15-rc5
v2.6.15-rc6
v2.6.15-rc7
v2.6.16
v2.6.16-rc1
v2.6.16-rc2
v2.6.16-rc3
v2.6.16-rc4
v2.6.16-rc5
v2.6.16-rc6
v2.6.17
v2.6.17-rc1
v2.6.17-rc2
v2.6.17-rc3
v2.6.17-rc4
v2.6.17-rc5
v2.6.17-rc6
v2.6.18
v2.6.18-rc1
v2.6.18-rc2
v2.6.18-rc3
v2.6.18-rc4
v2.6.18-rc5
v2.6.18-rc6
v2.6.18-rc7
v2.6.19
v2.6.19-rc1
v2.6.19-rc2
v2.6.19-rc3
v2.6.19-rc4
v2.6.19-rc5
v2.6.19-rc6
v2.6.20
v2.6.20-rc1
v2.6.20-rc2
v2.6.20-rc3
v2.6.20-rc4
v2.6.20-rc5
v2.6.20-rc6
v2.6.20-rc7
v2.6.21
v2.6.21-rc1
v2.6.21-rc2
v2.6.21-rc3
v2.6.21-rc4
v2.6.21-rc5
v2.6.21-rc6
v2.6.21-rc7
v2.6.22
v2.6.22-rc1
v2.6.22-rc2
v2.6.22-rc3
v2.6.22-rc4
v2.6.22-rc5
v2.6.22-rc6
v2.6.22-rc7
v2.6.23
v2.6.23-rc1
v2.6.23-rc2
v2.6.23-rc3
v2.6.23-rc4
v2.6.23-rc5
v2.6.23-rc6
v2.6.23-rc7
v2.6.23-rc8
v2.6.23-rc9
v2.6.24
v2.6.24-rc1
v2.6.24-rc2
v2.6.24-rc3
v2.6.24-rc4
v2.6.24-rc5
v2.6.24-rc6
v2.6.24-rc7
v2.6.24-rc8
v2.6.25
v2.6.25-rc1
v2.6.25-rc2
v2.6.25-rc3
v2.6.25-rc4
v2.6.25-rc5
v2.6.25-rc6
v2.6.25-rc7
v2.6.25-rc8
v2.6.25-rc9
v2.6.26
v2.6.26-rc1
v2.6.26-rc2
v2.6.26-rc3
v2.6.26-rc4
v2.6.26-rc5
v2.6.26-rc6
v2.6.26-rc7
v2.6.26-rc8
v2.6.26-rc9
v2.6.27
v2.6.27-rc1
v2.6.27-rc2
v2.6.27-rc3
v2.6.27-rc4
v2.6.27-rc5
v2.6.27-rc6
v2.6.27-rc7
v2.6.27-rc8
v2.6.27-rc9
v2.6.28
v2.6.28-rc1
v2.6.28-rc2
v2.6.28-rc3
v2.6.28-rc4
v2.6.28-rc5
v2.6.28-rc6
v2.6.28-rc7
v2.6.28-rc8
v2.6.28-rc9
v2.6.29
v2.6.29-rc1
v2.6.29-rc2
v2.6.29-rc3
v2.6.29-rc4
v2.6.29-rc5
v2.6.29-rc6
v2.6.29-rc7
v2.6.29-rc8
v2.6.30
v2.6.30-rc1
v2.6.30-rc2
v2.6.30-rc3
v2.6.30-rc4
v2.6.30-rc5
v2.6.30-rc6
v2.6.30-rc7
v2.6.30-rc8
v2.6.31
v2.6.31-rc1
v2.6.31-rc2
v2.6.31-rc3
v2.6.31-rc4
v2.6.31-rc5
v2.6.31-rc6
v2.6.31-rc7
v2.6.31-rc8
v2.6.31-rc9
v2.6.32
v2.6.32-rc1
v2.6.32-rc2
v2.6.32-rc3
v2.6.32-rc4
v2.6.32-rc5
v2.6.32-rc6
v2.6.32-rc7
v2.6.32-rc8
v2.6.33
v2.6.33-rc1
v2.6.33-rc2
v2.6.33-rc3
v2.6.33-rc4
v2.6.33-rc5
v2.6.33-rc6
v2.6.33-rc7
v2.6.33-rc8
v2.6.34
v2.6.34-rc1
v2.6.34-rc2
v2.6.34-rc3
v2.6.34-rc4
v2.6.34-rc5
v2.6.34-rc6
v2.6.34-rc7
v2.6.35
v2.6.35-rc1
v2.6.35-rc2
v2.6.35-rc3
v2.6.35-rc4
v2.6.35-rc5
v2.6.35-rc6
v2.6.36
v2.6.36-rc1
v2.6.36-rc2
v2.6.36-rc3
v2.6.36-rc4
v2.6.36-rc5
v2.6.36-rc6
v2.6.36-rc7
v2.6.36-rc8
v2.6.37
v2.6.37-rc1
v2.6.37-rc2
v2.6.37-rc3
v2.6.37-rc4
v2.6.37-rc5
v2.6.37-rc6
v2.6.37-rc7
v2.6.37-rc8
v2.6.38
v2.6.38-rc1
v2.6.38-rc2
v2.6.38-rc3
v2.6.38-rc4
v2.6.38-rc5
v2.6.38-rc6
v2.6.38-rc7
v2.6.38-rc8
v2.6.39
v2.6.39-rc1
v2.6.39-rc2
v2.6.39-rc3
v2.6.39-rc4
v2.6.39-rc5
v2.6.39-rc6
v2.6.39-rc7

v3.*

v3.0
v3.0-rc1
v3.0-rc2
v3.0-rc3
v3.0-rc4
v3.0-rc5
v3.0-rc6
v3.0-rc7
v3.1
v3.1-rc1
v3.1-rc10
v3.1-rc2
v3.1-rc3
v3.1-rc4
v3.1-rc5
v3.1-rc6
v3.1-rc7
v3.1-rc8
v3.1-rc9
v3.10
v3.10-rc1
v3.10-rc2
v3.10-rc3
v3.10-rc4
v3.10-rc5
v3.10-rc6
v3.10-rc7
v3.11
v3.11-rc1
v3.11-rc2
v3.11-rc3
v3.11-rc4
v3.11-rc5
v3.11-rc6
v3.11-rc7
v3.12
v3.12-rc1
v3.12-rc2
v3.12-rc3
v3.12-rc4
v3.12-rc5
v3.12-rc6
v3.12-rc7
v3.13
v3.13-rc1
v3.13-rc2
v3.13-rc3
v3.13-rc4
v3.13-rc5
v3.13-rc6
v3.13-rc7
v3.13-rc8
v3.14
v3.14-rc1
v3.14-rc2
v3.14-rc3
v3.14-rc4
v3.14-rc5
v3.14-rc6
v3.14-rc7
v3.14-rc8
v3.15
v3.15-rc1
v3.15-rc2
v3.15-rc3
v3.15-rc4
v3.15-rc5
v3.15-rc6
v3.15-rc7
v3.15-rc8
v3.16
v3.16-rc1
v3.16-rc2
v3.16-rc3
v3.16-rc4
v3.16-rc5
v3.16-rc6
v3.16-rc7
v3.17
v3.17-rc1
v3.17-rc2
v3.17-rc3
v3.17-rc4
v3.17-rc5
v3.17-rc6
v3.17-rc7
v3.18
v3.18-rc1
v3.18-rc2
v3.18-rc3
v3.18-rc4
v3.18-rc5
v3.18-rc6
v3.18-rc7
v3.19
v3.19-rc1
v3.19-rc2
v3.19-rc3
v3.19-rc4
v3.19-rc5
v3.19-rc6
v3.19-rc7
v3.2
v3.2-rc1
v3.2-rc2
v3.2-rc3
v3.2-rc4
v3.2-rc5
v3.2-rc6
v3.2-rc7
v3.3
v3.3-rc1
v3.3-rc2
v3.3-rc3
v3.3-rc4
v3.3-rc5
v3.3-rc6
v3.3-rc7
v3.4
v3.4-rc1
v3.4-rc2
v3.4-rc3
v3.4-rc4
v3.4-rc5
v3.4-rc6
v3.4-rc7
v3.5
v3.5-rc1
v3.5-rc2
v3.5-rc3
v3.5-rc4
v3.5-rc5
v3.5-rc6
v3.5-rc7
v3.6
v3.6-rc1
v3.6-rc2
v3.6-rc3
v3.6-rc4
v3.6-rc5
v3.6-rc6
v3.6-rc7
v3.7
v3.7-rc1
v3.7-rc2
v3.7-rc3
v3.7-rc4
v3.7-rc5
v3.7-rc6
v3.7-rc7
v3.7-rc8
v3.8
v3.8-rc1
v3.8-rc2
v3.8-rc3
v3.8-rc4
v3.8-rc5
v3.8-rc6
v3.8-rc7
v3.9
v3.9-rc1
v3.9-rc2
v3.9-rc3
v3.9-rc4
v3.9-rc5
v3.9-rc6
v3.9-rc7
v3.9-rc8

v4.*

v4.0
v4.0-rc1
v4.0-rc2
v4.0-rc3
v4.0-rc4
v4.0-rc5
v4.0-rc6
v4.0-rc7