- Issued:
- 2018-03-26
- Updated:
- 2018-03-26
RHSA-2018:0591 - Security Advisory
Synopsis
Critical: python-paramiko security and bug fix update
Type/Severity
Security Advisory: Critical
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
An update for python-paramiko is now available for Red Hat Enterprise Linux 7 Extras.
Red Hat Product Security has rated this update as having a security impact of Critical. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The python-paramiko package provides a Python module that implements the SSH2 protocol for encrypted and authenticated connections to remote machines. Unlike SSL, the SSH2 protocol does not require hierarchical certificates signed by a powerful central authority. The protocol also includes the ability to open arbitrary channels to remote services across an encrypted tunnel.
Security Fix(es):
- python-paramiko: Authentication bypass in transport.py (CVE-2018-7750)
For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
- python-paramiko has been using the python2-pyasn1 package, but did not depend on it. With new versions of python2-cryptography, python2-pyasn1 was not getting installed and this caused python-paramiko to malfunction. This bug was fixed by making python-paramiko depend on python2-pyasn1 explicitly. (BZ#1559133)
Solution
For details on how to apply this update, which includes the changes described in this advisory, refer to:
Affected Products
- Red Hat Enterprise Linux Server 7 x86_64
- Red Hat Enterprise Linux for Power, little endian 7 ppc64le
- Red Hat Enterprise Linux for Power 9 7 ppc64le
Fixes
- BZ - 1557130 - CVE-2018-7750 python-paramiko: Authentication bypass in transport.py
- BZ - 1559133 - Missing requirements in python-paramiko
CVEs
Red Hat Enterprise Linux Server 7
SRPM | |
---|---|
python-paramiko-2.1.1-4.el7.src.rpm | SHA-256: 43ba21a7cbfc99918164c9dee8e2c2ece5915b421834a00474d2bfbeb3d748b7 |
x86_64 | |
python-paramiko-2.1.1-4.el7.noarch.rpm | SHA-256: 461375b1b458818f5b5893aefac09fbf39cd651c081e63479915b8ffa33a72cc |
python-paramiko-doc-2.1.1-4.el7.noarch.rpm | SHA-256: 4abfc94c371f6fb64761ad9616522bfbab10091dc60cc0513f2496b70a883d36 |
Red Hat Enterprise Linux for Power, little endian 7
SRPM | |
---|---|
python-paramiko-2.1.1-4.el7.src.rpm | SHA-256: 43ba21a7cbfc99918164c9dee8e2c2ece5915b421834a00474d2bfbeb3d748b7 |
ppc64le | |
python-paramiko-2.1.1-4.el7.noarch.rpm | SHA-256: 461375b1b458818f5b5893aefac09fbf39cd651c081e63479915b8ffa33a72cc |
python-paramiko-doc-2.1.1-4.el7.noarch.rpm | SHA-256: 4abfc94c371f6fb64761ad9616522bfbab10091dc60cc0513f2496b70a883d36 |
Red Hat Enterprise Linux for Power 9 7
SRPM | |
---|---|
python-paramiko-2.1.1-4.el7.src.rpm | SHA-256: 43ba21a7cbfc99918164c9dee8e2c2ece5915b421834a00474d2bfbeb3d748b7 |
ppc64le | |
python-paramiko-2.1.1-4.el7.noarch.rpm | SHA-256: 461375b1b458818f5b5893aefac09fbf39cd651c081e63479915b8ffa33a72cc |
python-paramiko-doc-2.1.1-4.el7.noarch.rpm | SHA-256: 4abfc94c371f6fb64761ad9616522bfbab10091dc60cc0513f2496b70a883d36 |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.