Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 23

Количество 23

fstec логотип

BDU:2019-00830

больше 7 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю манипулировать файлами в каталоге клиента

CVSS3: 5.9
EPSS: Средний
ubuntu логотип

CVE-2019-6111

больше 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2019-6111

больше 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2019-6111

больше 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2019-6111

больше 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation ...

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-jr78-hfw4-xp7g

около 4 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2019-03788

больше 7 лет назад

Уязвимость средства криптографической защиты OpenSSH, вызваная ошибками при проверке имени каталога scp.c в клиенте scp, позволяющая нарушителю изменить права доступа к целевому каталогу

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2019:1602-1

около 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0307-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1524-1

около 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14030-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14016-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0941-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0496-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
rocky логотип

RLSA-2019:3702

6 дней назад

Moderate: openssh security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2019-3702

больше 6 лет назад

ELSA-2019-3702: openssh security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0093-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0091-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:13931-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0132-1

больше 7 лет назад

Security update for openssh

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-00830

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю манипулировать файлами в каталоге клиента

CVSS3: 5.9
58%
Средний
больше 7 лет назад
ubuntu логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
58%
Средний
больше 7 лет назад
redhat логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.3
58%
Средний
больше 7 лет назад
nvd логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
58%
Средний
больше 7 лет назад
debian логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation ...

CVSS3: 5.9
58%
Средний
больше 7 лет назад
github логотип
GHSA-jr78-hfw4-xp7g

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
58%
Средний
около 4 лет назад
fstec логотип
BDU:2019-03788

Уязвимость средства криптографической защиты OpenSSH, вызваная ошибками при проверке имени каталога scp.c в клиенте scp, позволяющая нарушителю изменить права доступа к целевому каталогу

CVSS3: 5.9
58%
Средний
больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1602-1

Security update for openssh

около 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0307-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1524-1

Security update for openssh

около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:14030-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:14016-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:0941-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:0496-1

Security update for openssh

больше 7 лет назад
rocky логотип
RLSA-2019:3702

Moderate: openssh security, bug fix, and enhancement update

6 дней назад
oracle-oval логотип
ELSA-2019-3702

ELSA-2019-3702: openssh security, bug fix, and enhancement update (MODERATE)

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0093-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0091-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:13931-1

Security update for openssh

больше 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:0132-1

Security update for openssh

больше 7 лет назад

Уязвимостей на страницу