PT-2019-1442 · Openssh+6 · Openssh+6

Harry Sintonen

·

Published

2018-11-06

·

Updated

2025-11-04

·

CVE-2019-6109

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions OpenSSH version 7.9
Description The issue is related to insufficient access control in the OpenSSH utility, specifically in the refresh progress meter() function. This can allow a remote attacker to disclose protected information or execute arbitrary code. Additionally, a malicious server or Man-in-The-Middle attacker can manipulate client output by using crafted object names, potentially hiding additional files being transferred. This is due to missing character encoding in the progress display. The vulnerability also affects the scp client, allowing remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename, which can modify the permissions of the target directory on the client side.
Recommendations For OpenSSH version 7.9, consider disabling the refresh progress meter() function until a patch is available. Restrict access to the scp client to minimize the risk of exploitation. Avoid using the scp client with untrusted SSH servers until the issue is resolved. As a temporary workaround, consider validating and sanitizing filenames received from remote SSH servers to prevent manipulation of client output.

Exploit

Fix

Improper Encoding or Escaping of Output

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2598
ALT-PU-2022-1557
ALT-PU-2022-1569
ALT-PU-2024-12010
ALT-PU-2024-12012
ALT-PU-2024-3921
ALT-PU-2024-4077
ALT-PU-2024-4467
ALT-PU-2024-9513
BDU:2019-00832
BDU:2019-03791
CESA-2019_3702
CVE-2019-6109
DLA-1728-1
DSA-4387-1
MGASA-2019-0156
OPENSUSE-SU-2019:0091-1
OPENSUSE-SU-2019:0307-1
OPENSUSE-SU-2019_0091-1
OPENSUSE-SU-2019_0093-1
OPENSUSE-SU-2019_0307-1
OPENSUSE-SU-2019_1602-1
OPENSUSE-SU-2024:11124-1
PAN-SA-2020-0002
RHSA-2019:3702
RHSA-2019_3702
ROSA-SA-2025-2551
SUSE-SU-2019:0125-1
SUSE-SU-2019:0125-2
SUSE-SU-2019:0126-1
SUSE-SU-2019:0132-1
SUSE-SU-2019:0496-1
SUSE-SU-2019:0941-1
SUSE-SU-2019:13931-1
SUSE-SU-2019:14016-1
SUSE-SU-2019:14030-1
SUSE-SU-2019:1524-1
SUSE-SU-2019_0496-1
SUSE-SU-2019_0941-1
SUSE-SU-2019_14030-1
SUSE-SU-2019_1524-1
USN-3885-1

Affected Products

Alt Linux
Centos
Ibm Aix
Openssh
Red Hat
Suse
Ubuntu