CVE-2017-15906
—CVSS 3.1
5.3 medium
EPSS
3%p88
Published
()
Modified
Description
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
- Vendors
- openbsdoracledebiannetappredhat
- Products
- openssh, sun zfs storage appliance kit, debian linux, active iq unified manager, cloud backup, clustered data ontap, data ontap edge, hci management node, oncommand unified manager core package, solidfire, steelstore cloud integrated storage, storage replication adapter for clustered data ontap
- Weakness
- CWE-732
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.