Логотип exploitDog
bind:CVE-2019-6111
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-6111

Количество 22

Количество 22

ubuntu логотип

CVE-2019-6111

больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
redhat логотип

CVE-2019-6111

почти 7 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2019-6111

больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2019-6111

больше 6 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation ...

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-jr78-hfw4-xp7g

больше 3 лет назад

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2019-03788

больше 6 лет назад

Уязвимость средства криптографической защиты OpenSSH, вызваная ошибками при проверке имени каталога scp.c в клиенте scp, позволяющая нарушителю изменить права доступа к целевому каталогу

CVSS3: 5.9
EPSS: Средний
fstec логотип

BDU:2019-00830

больше 6 лет назад

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю манипулировать файлами в каталоге клиента

CVSS3: 5.9
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2019:1602-1

около 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0307-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:1524-1

около 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14030-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:14016-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0941-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0496-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
oracle-oval логотип

ELSA-2019-3702

почти 6 лет назад

ELSA-2019-3702: openssh security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0093-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:0091-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:13931-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0132-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:0126-1

больше 6 лет назад

Security update for openssh

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
66%
Средний
больше 6 лет назад
redhat логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.3
66%
Средний
почти 7 лет назад
nvd логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
66%
Средний
больше 6 лет назад
debian логотип
CVE-2019-6111

An issue was discovered in OpenSSH 7.9. Due to the scp implementation ...

CVSS3: 5.9
66%
Средний
больше 6 лет назад
github логотип
GHSA-jr78-hfw4-xp7g

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

CVSS3: 5.9
66%
Средний
больше 3 лет назад
fstec логотип
BDU:2019-03788

Уязвимость средства криптографической защиты OpenSSH, вызваная ошибками при проверке имени каталога scp.c в клиенте scp, позволяющая нарушителю изменить права доступа к целевому каталогу

CVSS3: 5.9
66%
Средний
больше 6 лет назад
fstec логотип
BDU:2019-00830

Уязвимость реализаций утилиты для удаленного копирования файлов scp, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю манипулировать файлами в каталоге клиента

CVSS3: 5.9
66%
Средний
больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:1602-1

Security update for openssh

около 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0307-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:1524-1

Security update for openssh

около 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14030-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:14016-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0941-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0496-1

Security update for openssh

больше 6 лет назад
oracle-oval логотип
ELSA-2019-3702

ELSA-2019-3702: openssh security, bug fix, and enhancement update (MODERATE)

почти 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0093-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:0091-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:13931-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0132-1

Security update for openssh

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:0126-1

Security update for openssh

больше 6 лет назад

Уязвимостей на страницу