Vulnerability CVE-2019-6109: Information

Description

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

Severity: MEDIUM (6.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Published: Jan. 31, 2019
Modified: Nov. 7, 2023
Error type identifier: CWE-116

Fixed packages

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
      End including
      7.9

      cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*
      End including
      5.13

      Configuration 2

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

      cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*

      Configuration 3

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      Configuration 4

      cpe:2.3:a:netapp:element_software:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:storage_automation_store:-:*:*:*:*:*:*:*

      cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*

      Configuration 5

      cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*

      Configuration 6

      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:8.2:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:8.2:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:8.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:8.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:8.4:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_aus:8.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_server_tus:8.6:*:*:*:*:*:*:*

      cpe:2.3:o:redhat:enterprise_linux_eus:8.6:*:*:*:*:*:*:*

      Configuration 7

      cpe:2.3:o:siemens:scalance_x204rna_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:siemens:scalance_x204rna:-:*:*:*:*:*:*:*

      Configuration 8

      cpe:2.3:o:siemens:scalance_x204rna_eec_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:siemens:scalance_x204rna_eec:-:*:*:*:*:*:*:*

      Configuration 9

      cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*

      Configuration 10

      cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*

      Configuration 11

      cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

      Configuration 12

      cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*

      Configuration 13

      cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*

      Configuration 14

      cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*

      Configuration 15

      cpe:2.3:o:fujitsu:m10-1_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-1:-:*:*:*:*:*:*:*

      Configuration 16

      cpe:2.3:o:fujitsu:m10-4_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-4:-:*:*:*:*:*:*:*

      Configuration 17

      cpe:2.3:o:fujitsu:m10-4s_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m10-4s:-:*:*:*:*:*:*:*

      Configuration 18

      cpe:2.3:o:fujitsu:m12-1_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-1:-:*:*:*:*:*:*:*

      Configuration 19

      cpe:2.3:o:fujitsu:m12-2_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-2:-:*:*:*:*:*:*:*

      Configuration 20

      cpe:2.3:o:fujitsu:m12-2s_firmware:*:*:*:*:*:*:*:*

      Running on/with:
      cpe:2.3:h:fujitsu:m12-2s:-:*:*:*:*:*:*:*