Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mv2j-4mm8-9xgv

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

EPSS

Процентиль: 97%
0.20906
Средний

6.8 Medium

CVSS3

Дефекты

CWE-838

Связанные уязвимости

CVSS3: 6.8
ubuntu
больше 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
redhat
почти 8 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
nvd
больше 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
debian
больше 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr outpu ...

CVSS3: 6.8
fstec
больше 7 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостатками контроля доступа, позволяющая нарушителю скрывать имя передаваемого файла

EPSS

Процентиль: 97%
0.20906
Средний

6.8 Medium

CVSS3

Дефекты

CWE-838