Spoofing attack in WinSCP - CVE-2019-6109

 

Spoofing attack in WinSCP - CVE-2019-6109

Published: January 15, 2019


Vulnerability identifier: #VU16990
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6109
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct spoofing attack on the target system.

The weakness exists due to accepting and displaying arbitrary stderr output from the scp server by the scp client. A malicious SCP server can use the object name to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.

Affected software

WinSCP
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
Security Event Manager (SEM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)

How to mitigate CVE-2019-6109

Update to version 5.14.

WinSCP - update to 5.14
openssh (Ubuntu package) - addressed in versions 1:6.6p1-2ubuntu2.12, 1:7.2p2-4ubuntu2.7, 1:7.6p1-4ubuntu0.2, 1:7.7p1-4ubuntu0.2
Security Event Manager (SEM) - addressed in versions 2021.4, 2024.2
openssh (Debian package) - update to 1:7.4p1-10+deb9u5
openssh (Alpine package) - update to 7.5_p1-r4
pam_ssh_agent_auth - update to 0.10.3-7.13.0.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
openssh - update to 8.0p1-1.fc30
openssh - update to 8.0p1-13.0.1
openssh-askpass - update to 8.0p1-13.0.1
openssh-cavs - update to 8.0p1-13.0.1
openssh-clients - update to 8.0p1-13.0.1
openssh-keycat - update to 8.0p1-13.0.1
openssh-ldap - update to 8.0p1-13.0.1
openssh-server - update to 8.0p1-13.0.1

External References

Related Security Bulletins