Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv2j-4mm8-9xgv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

EPSS

Процентиль: 98%
0.51287
Средний

6.8 Medium

CVSS3

Дефекты

CWE-838

Связанные уязвимости

CVSS3: 6.8
ubuntu
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
redhat
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
nvd
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
debian
около 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr outpu ...

CVSS3: 6.8
fstec
около 7 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостатками контроля доступа, позволяющая нарушителю скрывать имя передаваемого файла

EPSS

Процентиль: 98%
0.51287
Средний

6.8 Medium

CVSS3

Дефекты

CWE-838