Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-6110

Опубликовано: 31 янв. 2019
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 4
CVSS3: 6.8

Описание

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

РелизСтатусПримечание
bionic

ignored

cosmic

ignored

end of life
devel

ignored

disco

ignored

end of life
eoan

ignored

esm-infra-legacy/trusty

ignored

esm-infra-legacy/xenial

ignored

esm-infra/bionic

ignored

esm-infra/focal

ignored

esm-infra/xenial

ignored

Показывать по

РелизСтатусПримечание
bionic

ignored

cosmic

ignored

end of life
devel

ignored

disco

ignored

end of life
eoan

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-infra-legacy/trusty

DNE

focal

ignored

precise/esm

DNE

Показывать по

EPSS

Процентиль: 97%
0.20906
Средний

4 Medium

CVSS2

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
redhat
почти 8 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
nvd
больше 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
debian
больше 7 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr outpu ...

CVSS3: 6.8
github
больше 4 лет назад

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

CVSS3: 6.8
fstec
больше 7 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостатками контроля доступа, позволяющая нарушителю скрывать имя передаваемого файла

EPSS

Процентиль: 97%
0.20906
Средний

4 Medium

CVSS2

6.8 Medium

CVSS3