ZeroHour

CVE-2017-15906

CVSS 3.1
5.3 medium
EPSS
3%p88
Published
()
Modified
Description

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

Vendors
openbsdoracledebiannetappredhat
Products
openssh, sun zfs storage appliance kit, debian linux, active iq unified manager, cloud backup, clustered data ontap, data ontap edge, hci management node, oncommand unified manager core package, solidfire, steelstore cloud integrated storage, storage replication adapter for clustered data ontap
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news

No ingested article mentions this CVE yet.