Spoofing attack in WinSCP - CVE-2019-6109
Published: January 15, 2019
Vulnerability identifier: #VU16990
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6109
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to conduct spoofing attack on the target system.
The weakness exists due to accepting and displaying arbitrary stderr output from the scp server by the scp client. A malicious SCP server can use the object name to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.
The weakness exists due to accepting and displaying arbitrary stderr output from the scp server by the scp client. A malicious SCP server can use the object name to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.
Affected software
WinSCP
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
Security Event Manager (SEM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Gentoo Linux
Amazon Linux AMI
Anolis OS
Red Hat Enterprise Linux for x86_64
Opensuse
Fedora
openssh (Ubuntu package)
openssh (Debian package)
openssh (Alpine package)
pam_ssh_agent_auth
openssh
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
Security Event Manager (SEM)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
How to mitigate CVE-2019-6109
Update to version 5.14.
WinSCP - update to 5.14
openssh (Ubuntu package) - addressed in versions 1:6.6p1-2ubuntu2.12, 1:7.2p2-4ubuntu2.7, 1:7.6p1-4ubuntu0.2, 1:7.7p1-4ubuntu0.2
Security Event Manager (SEM) - addressed in versions 2021.4, 2024.2
openssh (Debian package) - update to 1:7.4p1-10+deb9u5
openssh (Alpine package) - update to 7.5_p1-r4
pam_ssh_agent_auth - update to 0.10.3-7.13.0.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
openssh - update to 8.0p1-1.fc30
openssh - update to 8.0p1-13.0.1
openssh-askpass - update to 8.0p1-13.0.1
openssh-cavs - update to 8.0p1-13.0.1
openssh-clients - update to 8.0p1-13.0.1
openssh-keycat - update to 8.0p1-13.0.1
openssh-ldap - update to 8.0p1-13.0.1
openssh-server - update to 8.0p1-13.0.1
openssh (Ubuntu package) - addressed in versions 1:6.6p1-2ubuntu2.12, 1:7.2p2-4ubuntu2.7, 1:7.6p1-4ubuntu0.2, 1:7.7p1-4ubuntu0.2
Security Event Manager (SEM) - addressed in versions 2021.4, 2024.2
openssh (Debian package) - update to 1:7.4p1-10+deb9u5
openssh (Alpine package) - update to 7.5_p1-r4
pam_ssh_agent_auth - update to 0.10.3-7.13.0.1
Dell EMC Unity VSA Operating Environment (OE) - update to 5.0.0.0.5.116
Dell EMC Unity Operating Environment (OE) - update to 5.0.0.0.5.116
openssh - update to 8.0p1-1.fc30
openssh - update to 8.0p1-13.0.1
openssh-askpass - update to 8.0p1-13.0.1
openssh-cavs - update to 8.0p1-13.0.1
openssh-clients - update to 8.0p1-13.0.1
openssh-keycat - update to 8.0p1-13.0.1
openssh-ldap - update to 8.0p1-13.0.1
openssh-server - update to 8.0p1-13.0.1
External References
Related Security Bulletins
- Multiple vulnerabilities in SCP implementation in WinSCP
- OpenSUSE Linux update for openssh
- OpenSUSE Linux update for openssh
- Debian update for openssh
- Ubuntu update for OpenSSH
- OpenSUSE Linux update for openssh
- OpenSUSE Linux update for openssh
- Gentoo update for OpenSSH
- Amazon Linux AMI update for openssh
- Red Hat update for openssh
- Spoofing attack in openssh (Alpine package)
- Multiple vulnerabilities in Dell EMC Unity Family
- SolarWinds Security Event Manager (SEM) update for third-party components
- SolarWinds Security Event Manager (SEM) update for third-party components
- Anolis OS update for openssh
- Fedora 30 update for openssh