drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Ausführen beliebiger Kommandos in Paramiko (Aktualisierung)
Name: |
Ausführen beliebiger Kommandos in Paramiko (Aktualisierung) |
|
ID: |
USN-3603-2 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 ESM |
|
Datum: |
Di, 20. März 2018, 23:57 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-7750 |
|
Applikationen: |
Paramiko |
|
Update von: |
Ausführen beliebiger Kommandos in Paramiko |
|
Originalnachricht |
--===============1277595427547399746== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="yRA+Bmk8aPhU85Qt" Content-Disposition: inline
--yRA+Bmk8aPhU85Qt Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-3603-2 March 20, 2018
paramiko vulnerability ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 ESM
Summary:
Paramiko could be made to run programs if it received specially crafted network traffic.
Software Description: - paramiko: Make ssh v2 connections with Python
Details:
USN-3603-1 fixed a vulnerability in Paramiko. This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
Matthijs Kooijman discovered that Paramiko's SSH server implementation did not properly require authentication before processing requests. An unauthenticated remote attacker could possibly use this to execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 ESM: python-paramiko 1.7.7.1-2ubuntu1.1
After a standard system update you need to restart any applications using Paramiko's server implementation to make all the necessary changes.
References: https://usn.ubuntu.com/usn/usn-3603-2 https://usn.ubuntu.com/usn/usn-3603-1 CVE-2018-7750
--yRA+Bmk8aPhU85Qt Content-Type: application/pgp-signature; name="signature.asc"
-----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEpgY7tWAjCaQ8jrvULwmejQBegfQFAlqxYY4ACgkQLwmejQBe gfRGVQ//f73FogfNnhYdtZjJsl9HczLGmdyuMjw1pJTWuVlo3uIJfXg3RXuje45x vkOcDWEi3g0IWFUHno/5cjrj3oqYEtefRZGsvs7HfsR7JamPvj7MudU+0ew2V/P7 aYtYkkho1rEvpMgPzF99r8Z7C8tWJvEuRsLnTuDlj/uyOrDOkgLgvrIEfMpd8xXL 1pNgENuo+DQ5KNYmO0UfJwRxPAlDvpkilTxhw3YI5wXG5FmxJhw04boBlE0lEy1A l7pB1QR/jWUEXQJKN6Ny/PPDubCfboczmZpy+HFWuhtSU3pF4o9AA3BH7CslnbSG iHOAFEHcZtOAdlsJeAYMCgN3tdi5y4qTO8k52tw1mepgwudhQ8/7RmMiwz/r3tt0 ZwT5w4bocw+4MK3ycGRXaGcuCeo+ft/6JtzWdTlNAqpptvZjZsHn0ERCFbwLGbX/ lYg4/8Eeu1H1xQuVM1Izs5h0ZN3lJkMYFsYpj9mCQ0rHI6ATWqBa79Bfb0RTCzlk Ca+gKL2vcNIlVs2tFyv328G8DsMnV5c2Dp7/7m9ptaYYT+Tdsy8fliq1iIMcsHJa pa8g1L16o70mcK6w9G/jlvkjrO1uRMh2Jr9ngzZQLENjQSoK2l0Ff+MTpi6NVoK3 NEH8mI81xo8bqBVb3e9MdIgNNRynIAgcGkEN1s3emKpzVPEDGHA= =yr5K -----END PGP SIGNATURE-----
--yRA+Bmk8aPhU85Qt--
--===============1277595427547399746== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
|
|
|
|