Wind River Support Network

HomeDefectsLIN10-5337
Fixed

LIN10-5337 : Security Advisory - openssh - CVE-2018-20685

Created: Jan 15, 2019    Updated: Feb 11, 2019
Resolved Date: Jan 27, 2019
Found In Version: 10.17.41.1
Fix Version: 10.17.41.14
Severity: Standard
Applicable for: Wind River Linux LTS 17
Component/s: Userspace

Description

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename.

https://nvd.nist.gov/vuln/detail/CVE-2018-20685

CVEs


Live chat
Online