OS Command Injection in libssh - CVE-2019-14889

 

OS Command Injection in libssh - CVE-2019-14889

Published: December 11, 2019


Vulnerability identifier: #VU23508
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-14889
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to incorrect handling of the SCP command parameters when initiating the connection within the ssh_scp_new() function. A remote attacker can trick victim into using a specially crafted SCP command to connect to a remote SCP server and execute arbitrary commands on the target server with privileges of the current user.


Affected software

libssh
Gentoo Linux
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
Fedora
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
Opensuse
libssh (Ubuntu package)
libssh (Alpine package)
libssh
libssh (Red Hat package)
libssh-debugsource
libssh4-debuginfo-32bit
libssh4-32bit
libssh-config
libssh4
libssh4-debuginfo
libssh-devel
libssh4-32bit-debuginfo
Service Telemetry Framework
Dell Secure Connect Gateway
Red Hat OpenShift Serverless
Quay
OpenShift Data Foundation (formerly OpenShift Container Storage)
IBM Tivoli Storage Manager
MySQL Workbench
PowerStore X
PowerStore T
Storage Resource Manager
EMC Cloud Tiering Appliance
Dell EMC Storage Monitoring and Reporting (SMR)

How to mitigate CVE-2019-14889

Install updates from vendor's website.

libssh - addressed in versions 0.8.8, 0.9.3
libssh (Ubuntu package) - addressed in versions 0.6.3-4.3ubuntu0.5, 0.8.0~20170825.94fa1e38-1ubuntu0.5, 0.8.6-3ubuntu0.3, 0.9.0-1ubuntu1.3
libssh (Alpine package) - addressed in versions 0.7.6-r1, 0.7.6-r2, 0.8.8-r0
Red Hat OpenShift Serverless - addressed in versions 1.10.2, 1.11.0, 1.12.0
Quay - update to 3.3.3
libssh - addressed in versions 0.7.7-1.el7, 0.9.3-1.fc30, 0.9.3-1.fc31
libssh (Red Hat package) - update to 0.9.4-2.el8
libssh-debugsource - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo-32bit - update to 0.9.8-3.12.2
libssh4-32bit - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-config - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4 - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-debuginfo - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh-devel - addressed in versions 0.9.8-3.12.2, 0.9.8-150200.13.3.1
libssh4-32bit-debuginfo - update to 0.9.8-150200.13.3.1
PowerStore X - update to 3.2.1.4-2386214
PowerStore T - update to 4.0.0.2-2365061
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
Storage Resource Manager - update to 4.10.0.3
Dell Secure Connect Gateway - update to 5.24.00.14
EMC Cloud Tiering Appliance - update to 13.2.0.2.29

External References

Related Security Bulletins