CVE-2019-6110
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
- Openbsd Openssh
- ≤ 7.9
- Winscp
- ≤ 5.13
- Fix
- Available
- CVSS 3.1
- 6.8 MEDIUM
- EPSS
- 20.9% (97th percentile)
- Weakness
- CWE-838
- NVD status
- Modified
- Published
- 2019-01-31
CVE-2019-6110 at NVD
8 known exploits for CVE-2019-6110
Proof-of-concept code and exploit modules indexed by Sploitus
MAL-008
OpenSSH SCP Client - Write Arbitrary Files Exploit
OpenSSH 7.6p1 SCP Client - Multiple Vulnerabilities (SSHtranger Things) Exploit
SSHtranger Things SCP Client File Issue
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
SCP Client - Multiple Vulnerabilities (SSHtranger Things)
OpenSSH SCP Client - Write Arbitrary Files
OpenSSH SCP Client - Write Arbitrary Files