UBUNTU-CVE-2019-6111
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-6111
UBUNTU-CVE-2019-6111
Summary:
Details: An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
References: https://ubuntu.com/security/CVE-2019-6111, https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt, https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-January/037459.html, https://ubuntu.com/security/notices/USN-3885-1, https://ubuntu.com/security/notices/USN-3885-2, https://www.cve.org/CVERecord?id=CVE-2019-6111
Affected packages
Package
Name: openssh
Purl: pkg:deb/ubuntu/openssh@1:6.6p1-2ubuntu2.13?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
