MGASA-2019-0067 - Updated openssh packages fix security vulnerability

Publication date: 13 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0067.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-20685

In OpenSSH, scp.c in the scp client allows remote SSH servers to bypass
intended access restrictions via the filename of . or an empty filename
(CVE-2018-20685).

References:
- https://bugs.mageia.org/show_bug.cgi?id=24191
- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20685

SRPMS:
- 6/core/openssh-7.5p1-2.3.mga6

Mageia 2019-0067: openssh security update

In OpenSSH, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of

Summary

In OpenSSH, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename (CVE-2018-20685).

References

- https://bugs.mageia.org/show_bug.cgi?id=24191

- - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20685

Resolution

MGASA-2019-0067 - Updated openssh packages fix security vulnerability

SRPMS

- 6/core/openssh-7.5p1-2.3.mga6

Severity
Publication date: 13 Feb 2019
URL: https://advisories.mageia.org/MGASA-2019-0067.html
Type: security
CVE: CVE-2018-20685

Related News