CVE-2019-6109: Medium severity OpenBSD OpenSSH vulnerability
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refreshprogressmeter() in progressmeter.c.
Other sources
OpenSSH has a vulnerability in the scp client utility. Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.
External Reference:
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
Proposed Patch:
https://sintonen.fi/advisories/scp-name-validator.patch
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:7.9p1-6Fixed in 1:7.4p1-10+deb9u5 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3Fixed in 1:8.4p1-5+deb11u7Fixed in 1:9.2p1-2+deb12u10Fixed in 1:9.2p1-2+deb12u9Fixed in 1:10.0p1-7+deb13u4Fixed in 1:10.0p1-7+deb13u2Fixed in 1:10.3p1-5Fixed in 1:10.4p1-2
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6109?
CVE-2019-6109 has been classified as a moderate severity vulnerability.
How do I fix CVE-2019-6109?
To fix CVE-2019-6109, upgrade OpenSSH to version 1:7.9p1-6 or higher.
Who is affected by CVE-2019-6109?
CVE-2019-6109 affects various versions of OpenSSH, especially those up to 7.9.
What type of attack does CVE-2019-6109 allow?
CVE-2019-6109 allows a malicious server or Man-in-The-Middle attacker to manipulate client output.
Which systems are affected by CVE-2019-6109?
Systems using vulnerable versions of OpenSSH, including Debian, Ubuntu, and Red Hat Enterprise Linux, are affected by CVE-2019-6109.