CVE-2018-20685: Medium severity OpenBSD OpenSSH vulnerability
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename.
Upstream Patch:
https://github.com/openssh/openssh-portable/commit/6010c030 https://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/scp.c.diff?r1=1.197&r2=1.198&f=h
Other sources
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:7.9p1-5Fixed in 1:7.4p1-10+deb9u5 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3Fixed in 1:8.4p1-5+deb11u7Fixed in 1:9.2p1-2+deb12u10Fixed in 1:9.2p1-2+deb12u9Fixed in 1:10.0p1-7+deb13u4Fixed in 1:10.0p1-7+deb13u2Fixed in 1:10.3p1-5Fixed in 1:10.4p1-2
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20685?
CVE-2018-20685 is considered a medium severity vulnerability, allowing bypass of access restrictions in the OpenSSH scp client.
How do I fix CVE-2018-20685?
To fix CVE-2018-20685, update OpenSSH to version 7.9p1-5 or later.
Which software is affected by CVE-2018-20685?
CVE-2018-20685 affects OpenSSH version 7.9 and earlier, including variants in Debian and other distributions.
What is the impact of CVE-2018-20685?
The impact of CVE-2018-20685 is the potential for unauthorized file access due to improper filename handling.
Is CVE-2018-20685 relevant for my system?
CVE-2018-20685 is relevant if you are using an affected version of OpenSSH in your system or application.