Wind River Support Network

HomeDefectsLIN8-10386
Fixed

LIN8-10386 : Security Advisory - openssh - CVE-2018-20685

Created: Jan 15, 2019    Updated: Feb 2, 2019
Resolved Date: Jan 19, 2019
Found In Version: 8.0.0.28
Fix Version: 8.0.0.29
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename.

https://nvd.nist.gov/vuln/detail/CVE-2018-20685

CVEs


Live chat
Online