PT-2018-2486 · Openssh+6 · Openssh+6
Harry Sintonen
·
Publicado
2018-10-16
·
Atualizado
2025-12-17
·
CVE-2018-20685
CVSS v2.0
5.4
Média
| Vetor | AV:N/AC:H/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
OpenSSH version 7.9
Description
The issue is caused by errors in checking the directory name in the scp.c file in the scp client. This allows a remote attacker to modify the access permissions of the target directory by using a filename of "." or an empty filename. The impact is that the permissions of the target directory on the client side can be modified.
Recommendations
For OpenSSH version 7.9, consider disabling the
scp function until a patch is available to prevent remote SSH servers from bypassing intended access restrictions. Restrict access to the scp client to minimize the risk of exploitation. Avoid using the filename parameter with "." or empty values in the affected scp client until the issue is resolved.Correção
Incorrect Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Ibm Aix
Openssh
Red Hat
Suse
Ubuntu