Wind River Support Network

HomeDefectsLIN8-10367
Fixed

LIN8-10367 : Security Advisory - openssh - CVE-2019-6109

Created: Jan 15, 2019    Updated: Apr 9, 2019
Resolved Date: Apr 1, 2019
Found In Version: 8.0.0.28
Fix Version: 8.0.0.30
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

OpenSSH has a vulnerability in the scp client utility. Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.

https://nvd.nist.gov/vuln/detail/CVE-2019-6109 

CVEs


Live chat
Online