USN-3885-2
Dashboard / Vulnerabilities / USN-3885-2
USN-3885-2
Summary: openssh vulnerability
Details: USN-3885-1 fixed vulnerabilities in OpenSSH. It was discovered that the fix for CVE-2019-6111 turned out to be incomplete. This update fixes the problem. Original advisory details: Harry Sintonen discovered multiple issues in the OpenSSH scp utility. If a user or automated system were tricked into connecting to an untrusted server, a remote attacker could possibly use these issues to write to arbitrary files, change directory permissions, and spoof client output.
References: https://ubuntu.com/security/notices/USN-3885-2, https://ubuntu.com/security/CVE-2019-6111
Affected packages
Package
Name: openssh
Purl: pkg:deb/ubuntu/openssh@1:6.6p1-2ubuntu2.13?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
