Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2020-15778

Опубликовано: 24 июл. 2020
Источник: ubuntu
Приоритет: low
EPSS Средний
CVSS2: 6.8
CVSS3: 7.8

Описание

** DISPUTED ** scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

РелизСтатусПримечание
bionic

ignored

devel

ignored

esm-infra-legacy/trusty

ignored

esm-infra/bionic

ignored

esm-infra/focal

ignored

esm-infra/xenial

ignored

focal

ignored

precise/esm

ignored

trusty

ignored

end of standard support
trusty/esm

ignored

Показывать по

РелизСтатусПримечание
bionic

ignored

devel

ignored

esm-apps/bionic

ignored

esm-apps/focal

ignored

esm-infra-legacy/trusty

DNE

focal

ignored

precise/esm

DNE

trusty

DNE

trusty/esm

DNE

upstream

ignored

frozen on openssh 7.5p

Показывать по

EPSS

Процентиль: 98%
0.66112
Средний

6.8 Medium

CVSS2

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
почти 5 лет назад

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

CVSS3: 7.8
nvd
почти 5 лет назад

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

CVSS3: 7.8
msrc
почти 5 лет назад

Описание отсутствует

CVSS3: 7.8
debian
почти 5 лет назад

scp in OpenSSH through 8.3p1 allows command injection in the scp.c tor ...

rocky
около 2 месяцев назад

Moderate: openssh security update

EPSS

Процентиль: 98%
0.66112
Средний

6.8 Medium

CVSS2

7.8 High

CVSS3