Wind River Support Network

HomeDefectsLIN10-5317
Fixed

LIN10-5317 : Security Advisory - openssh - CVE-2019-6109

Created: Jan 15, 2019    Updated: Mar 27, 2019
Resolved Date: Mar 12, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.15
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

OpenSSH has a vulnerability in the scp client utility. Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.

https://nvd.nist.gov/vuln/detail/CVE-2019-6109 

CVEs


Live chat
Online