OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
BID:106741
CVE-2019-6111 |Info
OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
| Bugtraq ID: | 106741 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-6111 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 18 2019 12:00AM |
| Updated: | Jan 18 2019 12:00AM |
| Credit: | Harry Sintonen |
| Vulnerable: |
Redhat Enterprise Linux 7 OpenSSH OpenSSH 4.2 OpenSSH OpenSSH 4.1 OpenSSH OpenSSH 4.0 OpenSSH OpenSSH 3.7.1 OpenSSH OpenSSH 3.7 OpenSSH OpenSSH 3.6.1 OpenSSH OpenSSH 3.5 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.3 OpenSSH OpenSSH 3.2 OpenSSH OpenSSH 3.1 OpenSSH OpenSSH 3.0.2 OpenSSH OpenSSH 3.0.1 OpenSSH OpenSSH 3.0 OpenSSH OpenSSH 2.9.9 OpenSSH OpenSSH 2.9 OpenSSH OpenSSH 2.5.2 OpenSSH OpenSSH 2.5.1 OpenSSH OpenSSH 2.5 OpenSSH OpenSSH 2.3 OpenSSH OpenSSH 2.2 OpenSSH OpenSSH 2.1.1 OpenSSH OpenSSH 2.1 OpenSSH OpenSSH 1.2.3 OpenSSH OpenSSH 1.2.2 OpenSSH OpenSSH 7.9 OpenSSH OpenSSH 7.7 OpenSSH OpenSSH 7.6 OpenSSH OpenSSH 7.4 OpenSSH OpenSSH 7.3 OpenSSH OpenSSH 7.2 OpenSSH OpenSSH 7.1 OpenSSH OpenSSH 7.0 OpenSSH OpenSSH 6.9 OpenSSH OpenSSH 6.8 OpenSSH OpenSSH 6.7 OpenSSH OpenSSH 6.6 OpenSSH OpenSSH 6.5 OpenSSH OpenSSH 6.4 OpenSSH OpenSSH 6.3 OpenSSH OpenSSH 6.2 OpenSSH OpenSSH 6.1 OpenSSH OpenSSH 6.0 OpenSSH OpenSSH 5.8 OpenSSH OpenSSH 5.7 OpenSSH OpenSSH 5.6 OpenSSH OpenSSH 5.5 OpenSSH OpenSSH 5.4 OpenSSH OpenSSH 5.3 OpenSSH OpenSSH 5.2 OpenSSH OpenSSH 5.1 OpenSSH OpenSSH 5.0 OpenSSH OpenSSH 4.9 OpenSSH OpenSSH 4.8 OpenSSH OpenSSH 4.7 OpenSSH OpenSSH 4.6 OpenSSH OpenSSH 4.5 OpenSSH OpenSSH 4.4 OpenSSH OpenSSH 4.3.0 OpenSSH OpenSSH 1.127 OpenSSH OpenSSH 1.126 F5 Traffix SDC 5.1 F5 Traffix SDC 5.0 F5 Traffix SDC 4.4 |
| Not Vulnerable: | |
Discussion
OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
OpenSSH is prone to an arbitrary file-overwrite vulnerability.
Successful exploits may allow an attacker to overwrite arbitrary files in the context of the user running the affected application.
OpenSSH 7.9 and prior versions are vulnerable.
OpenSSH is prone to an arbitrary file-overwrite vulnerability.
Successful exploits may allow an attacker to overwrite arbitrary files in the context of the user running the affected application.
OpenSSH 7.9 and prior versions are vulnerable.
Exploit / POC
OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
OpenSSH CVE-2019-6111 Arbitrary File Overwrite Vulnerability
References:
References:
- OpenSSH Home Page (OpenBSD)
- scp client multiple vulnerabilities (Sintonen)
- Bug 1666127 CVE-2019-6111 openssh: Improper validation of object names (Redhat)
- CVE-2019-6111 (Redhat)
- K21350967: OpenSSH vulnerability CVE-2019-6111 (F5)