CVE-2019-6109
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6109?
CVE-2019-6109 has been classified as a moderate severity vulnerability.
How do I fix CVE-2019-6109?
To fix CVE-2019-6109, upgrade OpenSSH to version 1:7.9p1-6 or higher.
Who is affected by CVE-2019-6109?
CVE-2019-6109 affects various versions of OpenSSH, especially those up to 7.9.
What type of attack does CVE-2019-6109 allow?
CVE-2019-6109 allows a malicious server or Man-in-The-Middle attacker to manipulate client output.
Which systems are affected by CVE-2019-6109?
Systems using vulnerable versions of OpenSSH, including Debian, Ubuntu, and Red Hat Enterprise Linux, are affected by CVE-2019-6109.