Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-6110

Опубликовано: 31 янв. 2019
Источник: debian

Описание

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
opensshunfixedpackage

Примечания

  • https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt

  • Not considered a vulnerability by upstream, cf.

  • https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-January/037475.html

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
redhat
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
nvd
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
github
больше 3 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
fstec
около 7 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостатками контроля доступа, позволяющая нарушителю скрывать имя передаваемого файла