CVE-2019-6110
Summary
| CVE | CVE-2019-6110 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-31 18:29:00 UTC |
| Updated | 2023-02-23 23:29:00 UTC |
| Description | In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| OpenSSH: Multiple vulnerabilities (GLSA 201903-16) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| SCP Client - Multiple Vulnerabilities (SSHtranger Things) - Multiple remote Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf |
CONFIRM |
cert-portal.siemens.com |
|
| CVS log for src/usr.bin/ssh/progressmeter.c |
MISC |
cvsweb.openbsd.org |
Release Notes, Vendor Advisory |
| January 2019 OpenSSH Vulnerabilities in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
Third Party Advisory |
| CVS log for src/usr.bin/ssh/scp.c |
MISC |
cvsweb.openbsd.org |
Release Notes, Vendor Advisory |
| sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt |
MISC |
sintonen.fi |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591280 Siemens SCALANCE X-200RNA Switch Devices Denial of Service (DoS) Multiple Vulnerabilities (ICSA-22-349-21, SSA-412672)
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)