Уязвимость CVE-2019-6111: Информация

Описание

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

Важность: MEDIUM (5,9) Вектор: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Опубликовано: 31 января 2019 г.
Изменено: 7 ноября 2023 г.
Идентификатор типа ошибки: CWE-22

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
opensshsisyphus7.9p1-alt19.6p1-alt1ALT-PU-2018-2598-1215513Исправлено
opensshp107.9p1-alt4.p10.17.9p1-alt4.p10.6ALT-PU-2022-1557-1297014Исправлено
opensshp10_e2k7.9p1-alt4.p10.17.9p1-alt4.p10.5ALT-PU-2022-4375-1-Исправлено
opensshp97.9p1-alt17.9p1-alt1ALT-PU-2018-2598-1215513Исправлено
opensshc10f17.9p1-alt4.p10.17.9p1-alt4.p10.6ALT-PU-2022-1557-1297014Исправлено
opensshc9f27.9p1-alt4.p10.17.9p1-alt4.p10.6ALT-PU-2022-1569-1297070Исправлено
openssh-gostcryptop107.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.3ALT-PU-2024-3921-3342647Исправлено
openssh-gostcryptoc10f17.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.3ALT-PU-2024-4467-2342830Исправлено
openssh-gostcryptoc9f27.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.3ALT-PU-2024-4077-2342832Исправлено

Ссылки на рекомендации, решения и инструменты

Ссылка
Ресурс
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
  • Third Party Advisory
https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.c
  • Release Notes
46193
  • Exploit
  • Third Party Advisory
  • VDB Entry
106741
  • Broken Link
  • Third Party Advisory
  • VDB Entry
USN-3885-1
  • Third Party Advisory
DSA-4387
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20190213-0001/
  • Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1677794
  • Exploit
  • Issue Tracking
  • Third Party Advisory
USN-3885-2
  • Third Party Advisory
GLSA-201903-16
  • Third Party Advisory
[debian-lts-announce] 20190325 [SECURITY] [DLA 1728-1] openssh security update
  • Mailing List
  • Third Party Advisory
[oss-security] 20190417 Announce: OpenSSH 8.0 released
  • Mailing List
  • Third Party Advisory
openSUSE-SU-2019:1602
  • Broken Link
FreeBSD-EN-19:10
  • Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
  • Patch
  • Third Party Advisory
RHSA-2019:3702
  • Third Party Advisory
[oss-security] 20220802 CVE-2022-29154: Rsync client-side arbitrary file write vulnerability.
  • Mailing List
  • Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
  • Third Party Advisory
FEDORA-2019-0f4190cdb0
    [mina-dev] 20190620 [jira] [Created] (SSHD-925) See if SCP vulnerability CVE-2019-6111 applies and mitigate it if so
      [mina-dev] 20190623 [jira] [Comment Edited] (SSHD-925) See if SCP vulnerability CVE-2019-6111 applies and mitigate it if so
        [mina-dev] 20190623 [jira] [Commented] (SSHD-925) See if SCP vulnerability CVE-2019-6111 applies and mitigate it if so
          [mina-dev] 20190820 [jira] [Resolved] (SSHD-925) See if SCP vulnerability CVE-2019-6111 applies and mitigate it if so
              1. Конфигурация 1

                cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
                End including
                7.9

                cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*
                End including
                5.1.3

                Конфигурация 2

                cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

                cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

                cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

                cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

                Конфигурация 3

                cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

                cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

                Конфигурация 4

                cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*

                cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*

                Конфигурация 5

                cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

                Конфигурация 6

                cpe:2.3:a:apache:mina_sshd:2.2.0:*:*:*:*:*:*:*

                Конфигурация 7

                cpe:2.3:o:freebsd:freebsd:12.0:p1:*:*:*:*:*:*

                cpe:2.3:o:freebsd:freebsd:12.0:-:*:*:*:*:*:*

                cpe:2.3:o:freebsd:freebsd:12.0:p3:*:*:*:*:*:*

                cpe:2.3:o:freebsd:freebsd:12.0:p2:*:*:*:*:*:*

                cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
                End excliding
                12.0

                Конфигурация 8

                cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*

                Конфигурация 9

                cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*

                Конфигурация 10

                cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

                Конфигурация 11

                cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*

                Конфигурация 12

                cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*

                Конфигурация 13

                cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*

                Конфигурация 14

                cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*

                Конфигурация 15

                cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*

                Конфигурация 16

                cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

                Конфигурация 17

                cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*

                Конфигурация 18

                cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*

                Конфигурация 19

                cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*

                Конфигурация 20

                cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:siemens:scalance_x204rna:-:*:*:*:*:*:*:*

                Конфигурация 21

                cpe:2.3:o:siemens:scalance_x204rna_eec_firmware:*:*:*:*:*:*:*:*

                Running on/with:
                cpe:2.3:h:siemens:scalance_x204rna_eec:-:*:*:*:*:*:*:*