Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pqm-q853-jfvf

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

EPSS

Процентиль: 92%
0.08073
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-116

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 3.1
redhat
почти 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
nvd
больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

CVSS3: 6.8
debian
больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to missing character encod ...

CVSS3: 6.8
fstec
больше 6 лет назад

Уязвимость функции refresh_progress_meter() (progressmeter.c) средства криптографической защиты OpenSSH, позволяющая нарушителю раскрыть защищаемую информацию или выполнить произвольный код

EPSS

Процентиль: 92%
0.08073
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-116