#VU16946 Security restrictions bypass in OpenSSH - CVE-2018-20685
Published: January 10, 2019 / Updated: January 16, 2019
OpenSSH
OpenSSH
Description
The vulnerability allows a remote attacker to bypass security restrictions on the target system.
The vulnerability exists due to improper validation of filenames by the scp.c source code file in the SCP client . A remote unauthenticated attacker can trick the victim into accessing a file with the filename of . or an empty filename from an attacker-controlled Secure Shell (SSH) server to bypass access restrictions on the system, which could be used to conduct further attacks.