Vulnerability Description
An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered cases where an absolute path is passed to scp. When a relative path is used, there is no verification that the name of a file received by the client matches the file requested. Fixed packages are available with numbers 7.4p1-22.78.amzn1 and 7.4p1-22.amzn2.0.2.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://alas.aws.amazon.com/cve/html/CVE-2023-35812.html
- https://alas.aws.amazon.com/cve/html/CVE-2023-35812.html
FAQ
What is CVE-2023-35812?
CVE-2023-35812 is a vulnerability with a CVSS score of 5.3 (MEDIUM). An issue was discovered in the Amazon Linux packages of OpenSSH 7.4 for Amazon Linux 1 and 2, because of an incomplete fix for CVE-2019-6111 within these specific packages. The fix had only covered ca...
How severe is CVE-2023-35812?
CVE-2023-35812 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-35812?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.