Vulnerability Description
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openbsd | Openssh | <= 7.9 |
| Winscp | Winscp | <= 5.13 |
| Canonical | Ubuntu Linux | 14.04 |
| Debian | Debian Linux | 8.0 |
| Netapp | Element Software | - |
| Netapp | Ontap Select Deploy | - |
| Netapp | Storage Automation Store | - |
| Fedoraproject | Fedora | 30 |
| Redhat | Enterprise Linux | 8.0 |
| Redhat | Enterprise Linux Eus | 8.1 |
| Redhat | Enterprise Linux Server Aus | 8.2 |
| Redhat | Enterprise Linux Server Tus | 8.2 |
| Siemens | Scalance X204Rna Firmware | < 3.2.7 |
| Siemens | Scalance X204Rna | - |
| Siemens | Scalance X204Rna Eec Firmware | < 3.2.7 |
| Siemens | Scalance X204Rna Eec | - |
| Fujitsu | M10-1 Firmware | < xcp2361 |
| Fujitsu | M10-1 | - |
| Fujitsu | M10-4 Firmware | < xcp2361 |
| Fujitsu | M10-4 | - |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.htmlBroken Link
- https://access.redhat.com/errata/RHSA-2019:3702Third Party Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfPatchThird Party Advisory
- https://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.cRelease NotesVendor Advisory
- https://cvsweb.openbsd.org/src/usr.bin/ssh/scp.cRelease NotesVendor Advisory
- https://lists.debian.org/debian-lts-announce/2019/03/msg00030.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/201903-16Third Party Advisory
- https://security.netapp.com/advisory/ntap-20190213-0001/Third Party Advisory
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtThird Party Advisory
- https://usn.ubuntu.com/3885-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4387Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatchThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.htmlBroken Link
- https://access.redhat.com/errata/RHSA-2019:3702Third Party Advisory
FAQ
What is CVE-2019-6109?
CVE-2019-6109 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the ...
How severe is CVE-2019-6109?
CVE-2019-6109 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6109?
Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh, Winscp Winscp, Canonical Ubuntu Linux, Debian Debian Linux, Netapp Element Software.