Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-6111

Опубликовано: 31 янв. 2019
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 5.8
CVSS3: 5.9

Описание

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

РелизСтатусПримечание
bionic

released

1:7.6p1-4ubuntu0.3
cosmic

released

1:7.7p1-4ubuntu0.3
devel

not-affected

1:7.9p1-10
disco

not-affected

1:7.9p1-10
eoan

not-affected

1:7.9p1-10
esm-infra-legacy/trusty

not-affected

1:6.6p1-2ubuntu2.13
esm-infra/bionic

not-affected

1:7.6p1-4ubuntu0.3
esm-infra/focal

not-affected

1:7.9p1-10
esm-infra/xenial

not-affected

1:7.2p2-4ubuntu2.8
fips-preview/jammy

not-affected

1:7.9p1-10

Показывать по

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

ignored

disco

ignored

end of life
eoan

ignored

end of life
esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-apps/jammy

ignored

esm-apps/noble

ignored

esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 98%
0.57154
Средний

5.8 Medium

CVSS2

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
почти 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
nvd
больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
debian
больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation ...

CVSS3: 5.9
github
больше 3 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
fstec
больше 6 лет назад

Уязвимость средства криптографической защиты OpenSSH, вызваная ошибками при проверке имени каталога scp.c в клиенте scp, позволяющая нарушителю изменить права доступа к целевому каталогу

EPSS

Процентиль: 98%
0.57154
Средний

5.8 Medium

CVSS2

5.9 Medium

CVSS3