PT-2023-25330 · Openssh · Openssh

Publicado

2023-08-09

·

Atualizado

2025-03-25

·

CVE-2023-35812

CVSS v3.1

5.3

Média

VetorAC:H/AV:N/A:N/C:N/I:H/PR:N/S:U/UI:R
Name of the Vulnerable Software and Affected Versions OpenSSH versions 7.4
Description An issue was discovered in OpenSSH because of an incomplete fix. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested.
Recommendations For OpenSSH version 7.4, update to fixed packages with numbers 7.4p1-22.78.amzn1 for Amazon Linux 1 and 7.4p1-22.amzn2.0.2 for Amazon Linux 2.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35812

Produtos afetados

Openssh