MGASA-2019-0156

    Dashboard / Vulnerabilities / MGASA-2019-0156

    MGASA-2019-0156

    Published: 12 May 2019Last Modified: 16 Apr 2026

    Summary: Updated openssh packages fix security vulnerabilities

    Details: Updated openssh packages fix security vulnerabilities: Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred (CVE-2019-6109). Due to scp client insufficient input validation in path names sent by server, a malicious server can do arbitrary file overwrites in target directory. If the recursive (-r) option is provided, the server can also manipulate subdirectories as well (CVE-2019-6111). The check added in this version can lead to regression if the client and the server have differences in wildcard expansion rules. If the server is trusted for that purpose, the check can be disabled with a new -T option to the scp client.

    Affected packages

    Package

    Name: openssh

    Purl: pkg:rpm/mageia/openssh?arch=source&distro=mageia-6

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7.5p1-2.4.mga6

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    MGASA-2019-0156 | CVE-DB