openssh: Improper validation of object names allows malicious server to overwrite files via scp client
Published Jan 31, 2019
5.9
MEDIUMCVSS 3.1
EPSS 58.20%
Description
An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).
Affected products
No data.
Configuration 2
- 14.04
- 16.04
- 18.04
- 18.10
Configuration 3
- 8.0
- 9.0
Configuration 4
- 7.0
- 8.0
- 8.1
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
- 8.2
- 8.4
- 8.6
Configuration 5
- 30
Configuration 7
Configuration 8
- < xcp2361
Configuration 9
- < xcp2361
Configuration 10
- < xcp2361
Configuration 11
- < xcp2361
Configuration 12
- < xcp2361
Configuration 13
- < xcp2361
Configuration 14
- < xcp3070
Configuration 15
- < xcp3070
Configuration 16
- < xcp3070
Configuration 17
- < xcp3070
Configuration 18
- < xcp3070
Configuration 19
- < xcp3070
Configuration 20
- < 3.2.7
Running on/with
- n/a
Configuration 21
- < 3.2.7
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 8
openssh-0:8.0p1-3.el8
Fixed · RHSA-2019:3702
Red Hat Enterprise Linux 8
openssh-0:8.0p1-3.el8
Fixed · RHSA-2019:3702
Red Hat Enterprise Linux 5
openssh
Out of support scope
Red Hat Enterprise Linux 6
openssh
Out of support scope
Red Hat Enterprise Linux 7
openssh
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-3.el8 | Fixed | RHSA-2019:3702 |
| Red Hat Enterprise Linux 8 | openssh-0:8.0p1-3.el8 | Fixed | RHSA-2019:3702 |
| Red Hat Enterprise Linux 5 | openssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | openssh | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | openssh | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the scp client shipped with openssh. The SSH protocol or the SSH client is not affected. For more detailed analysis please refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1666127#c2
Red Hat mitigation
This issue only affects the users of scp binary which is a part of openssh-clients package. Other usage of SSH protocol or other ssh clients is not affected. Administrators can uninstall openssh-clients for additional protection against accidental usage of this binary. Removal of openssh-clients package will make the packaged binaries like scp, ssh etc unavailable. Note: This flaw requires a malicious MITM scp server for exploitation. Use cases where trusted SCP servers are used are not affected by this flaw.
References (27)
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.html vendor-advisoryBroken Link
- http://www.openwall.com/lists/oss-security/2019/04/18/1 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2022/08/02/1 mailing-listMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/106741 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:3702 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-6111 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1666127 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=1677794 ExploitIssue TrackingThird Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf Third Party Advisory
- https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c Release Notes
- https://lists.apache.org/thread.html/c45d9bc90700354b58fb7455962873c44229841880dcb64842fa7d23%40%3Cdev.mina.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/c7301cab36a86825359e1b725fc40304d1df56dc6d107c1fe885148b%40%3Cdev.mina.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/d540139359de999b0f1c87d05b715be4d7d4bec771e1ae55153c5c7a%40%3Cdev.mina.apache.org%3E mailing-list
- https://lists.apache.org/thread.html/e47597433b351d6e01a5d68d610b4ba195743def9730e49561e8cf3f%40%3Cdev.mina.apache.org%3E mailing-list
- https://lists.debian.org/debian-lts-announce/2019/03/msg00030.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W3YVQ2BPTOVDCFDVNC2GGF5P5ISFG37G/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-6111
- https://security.gentoo.org/glsa/201903-16 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20190213-0001/ Third Party Advisory
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt Third Party Advisory
- https://usn.ubuntu.com/3885-1/ vendor-advisoryThird Party Advisory
- https://usn.ubuntu.com/3885-2/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-6111
- https://www.debian.org/security/2019/dsa-4387 vendor-advisoryThird Party Advisory
- https://www.exploit-db.com/exploits/46193/ exploitThird Party AdvisoryVDB Entry
- https://www.freebsd.org/security/advisories/FreeBSD-EN-19:10.scp.asc vendor-advisoryThird Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.