USN-3796-3: Paramiko vulnerability
Published Oct 22, 2018
·Updated
USN-3796-1 fixed a vulnerability in Paramiko. This update provides the corresponding update for Ubuntu 18.10. Original advisory details: Daniel Hoffman discovered that Paramiko incorrectly handled authentication when being used as a server. A remote attacker could use this issue to bypass authentication without any credentials.
Affected Software
1 affected component
pypi/paramiko
Event History
Feb 20, 2026
Advisory Published
via Ubuntu·03:40 PM
Data Sourced
via Ubuntu·03:40 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Paramiko vulnerability?
The vulnerability ID is USN-3796-3.
2
What is the affected software?
The affected software is python3-paramiko version 2.4.1-0ubuntu3.1 on Ubuntu 18.10.
3
How can an attacker exploit this vulnerability?
An attacker can bypass authentication when Paramiko is used as a server.
4
How can I fix this vulnerability?
You can fix this vulnerability by updating to version 2.4.1-0ubuntu3.1 of python3-paramiko.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu security website.