ZeroHour
Ubuntu Security Noticespublished ()ingested

USN-8514-2: OpenSSH vulnerability

mediumVulnerabilityimportance 35
AI summary · glm-5.3-flash

Ubuntu backports an OpenSSH fix to older LTS releases for an scp flaw enabling setuid file placement and privilege escalation.

USN-8514-2 extends the USN-8514-1 OpenSSH fix to Ubuntu 14.04 LTS, 18.04 LTS, and 20.04 LTS. The flaw stems from incorrect file permission handling when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could exploit this to install setuid or setgid files on the system, potentially leading to privilege escalation.

  • Flaw affects root scp downloads via legacy protocol without preserve-mode
  • Enables planting setuid/setgid files, possibly leading to privilege escalation
  • Update applies the USN-8514-1 fix to Ubuntu 14.04, 18.04, and 20.04 LTS
VendorsCanonical
ProductsOpenSSH
OrganizationsUbuntu
Full article

USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that OpenSSH incorrectly handled file permissions when downloading files as root using the legacy scp protocol without the preserve-mode option. An attacker could use this to install setuid or setgid files on a system, possibly leading to privilege escalation.

This source does not provide full text. Read it at ubuntu.com.