ELA-583-1 paramiko security update

information disclosure

2022-03-21
Packageparamiko
Version1.15.1-1+deb8u2
Related CVEs CVE-2022-24302


It was discovered that there was a potential race condition in Paramiko, a pure-Python implementation of the SSH algorithm. In particular, unauthorised information disclosure could have occurred during the creation of SSH private keys.



For Debian 8 Jessie, these problems have been fixed in version 1.15.1-1+deb8u2.

We recommend that you upgrade your paramiko packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.