ZeroHour

CVE-2018-20685

CVSS 3.1
5.3 medium
EPSS
4%p89
Published
()
Modified
Description

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

Vendors
openbsdwinscpnetappdebiancanonicalredhatoraclefujitsusiemens
Products
openssh, winscp, cloud backup, element software, ontap select deploy, steelstore cloud integrated storage, storage automation store, debian linux, ubuntu linux, enterprise linux, enterprise linux eus, enterprise linux server aus
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news