CVE-2019-14889
Summary
| CVE | CVE-2019-14889 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-12-10 23:15:00 UTC |
| Updated | 2023-11-07 03:05:00 UTC |
| Description | A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 31 Update: libssh-0.9.3-1.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| libssh: Arbitrary command execution (GLSA 202003-27) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| www.libssh.org/security/advisories/CVE-2019-14889.txt |
CONFIRM |
www.libssh.org |
Vendor Advisory |
| [SECURITY] [DLA 3437-1] libssh security update |
MLIST |
lists.debian.org |
|
| USN-4219-1: libssh vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: libssh-0.9.3-1.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2038-1] libssh security update |
MLIST |
lists.debian.org |
Mailing List, Third Party Advisory |
| 1772523 – (CVE-2019-14889) CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Patch, Third Party Advisory |
| [SECURITY] Fedora 30 Update: libssh-0.9.3-1.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2689-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 30 Update: libssh-0.9.3-1.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Oracle Critical Patch Update Advisory - April 2020 |
N/A |
www.oracle.com |
Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0102-1: important: Security update |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 181812 Debian Security Update for libssh (DLA 3437-1)
- 377559 Alibaba Cloud Linux Security Update for libssh (ALINUX3-SA-2022:0067)
- 501062 Alpine Linux Security Update for libssh
- 755806 SUSE Enterprise Linux Security Update for libssh (SUSE-SU-2024:0539-1)
- 770068 Red Hat OpenShift Container Platform 4.6 Security Update (RHSA-2021:0436)
- 940406 AlmaLinux Security Update for libssh (ALSA-2020:4545)
- 960879 Rocky Linux Security Update for libssh (RLSA-2020:4545)