CVE-2017-15906
published 2017-10-26CVE-2017-15906: The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create…
PriorityP431medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
3.36%
87.4th percentile
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | openssh | < openssh 1:7.6p1-1 (bookworm) | openssh 1:7.6p1-1 (bookworm) |
| netapp | storage_replication_adapter_for_clustered_data_ontap | — | — |
| netapp | storage_replication_adapter_for_clustered_data_ontap | >= 9.7 | — |
| netapp | vasa_provider_for_clustered_data_ontap | 6.0 – 6.2 | — |
| netapp | vasa_provider_for_clustered_data_ontap | >= 9.7 | — |
| netapp | virtual_storage_console | — | — |
| netapp | virtual_storage_console | >= 9.7 | — |
| openbsd | openssh | < 7.6 | 7.6 |
| openbsd | openssh | >= 0 < 1:7.6p1-1 | 1:7.6p1-1 |
| openbsd | openssh | >= 0 < 1:7.6p1-1 | 1:7.6p1-1 |
| openbsd | openssh | >= 0 < 1:7.6p1-1 | 1:7.6p1-1 |
| openbsd | openssh | >= 0 < 1:7.6p1-1 | 1:7.6p1-1 |
| openbsd | openssh | >= 0 < 1:6.6p1-2ubuntu2.10 | 1:6.6p1-2ubuntu2.10 |
| openbsd | openssh | >= 0 < 1:7.2p2-4ubuntu2.4 | 1:7.2p2-4ubuntu2.4 |
| oracle | sun_zfs_storage_appliance_kit | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.3HIGH
vendor_ubuntu7.3HIGH
vendor_debian5.3LOW
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenSSH up to 7.5 Readonly Mode sftp-server.c process_open permission (RHSA-2018:0980 / Nessus ID 104824)
vuldb·2026-05-29·CVSS 5.3
CVE-2017-15906 [MEDIUM] OpenSSH up to 7.5 Readonly Mode sftp-server.c process_open permission (RHSA-2018:0980 / Nessus ID 104824)
A vulnerability classified as critical was found in OpenSSH up to 7.5. Affected by this issue is the function process_open of the file sftp-server.c of the component Readonly Mode. Such manipulation leads to permission issues.
This vulnerability is documented as CVE-2017-15906. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
GHSA-543w-q592-87ph: The process_open function in sftp-server
ghsa_unreviewed·2022-05-13
CVE-2017-15906 [MEDIUM] CWE-732 GHSA-543w-q592-87ph: The process_open function in sftp-server
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
OSV
openssh vulnerabilities
osv·2018-01-22·CVSS 7.3
CVE-2016-10009 [HIGH] openssh vulnerabilities
openssh vulnerabilities
Jann Horn discovered that OpenSSH incorrectly loaded PKCS#11 modules from
untrusted directories. A remote attacker could possibly use this issue to
execute arbitrary PKCS#11 modules. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2016-10009)
Jann Horn discovered that OpenSSH incorrectly handled permissions on
Unix-domain sockets when privilege separation is disabled. A local attacker
could possibly use this issue to gain privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-10010)
Jann Horn discovered that OpenSSH incorrectly handled certain buffer memory
operations. A local attacker could possibly use this issue to obtain
sensitive information. This issue only affected Ubuntu 14.04 LTS and Ubuntu
16.04 LTS. (CVE-2016-10011)
Guid
OSV
CVE-2017-15906: The process_open function in sftp-server
osv·2017-10-26·CVSS 5.3
CVE-2017-15906 [MEDIUM] CVE-2017-15906: The process_open function in sftp-server
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2018-01-22·CVSS 7.3
CVE-2016-10009 [HIGH] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
Jann Horn discovered that OpenSSH incorrectly loaded PKCS#11 modules from
untrusted directories. A remote attacker could possibly use this issue to
execute arbitrary PKCS#11 modules. This issue only affected Ubuntu 14.04
LTS and Ubuntu 16.04 LTS. (CVE-2016-10009)
Jann Horn discovered that OpenSSH incorrectly handled permissions on
Unix-domain sockets when privilege separation is disabled. A local attacker
could possibly use this issue to gain privileges. This issue only affected
Ubuntu 16.04 LTS. (CVE-2016-10010)
Jann Horn discovered that OpenSSH incorrectly handled certain buffer memory
operations. A local attacker could possibly use this issue to obtain
sensitive information. This issue only affect
Red Hat
openssh: Improper write operations in readonly mode allow for zero-length file creation
vendor_redhat·2017-10-03·CVSS 5.3
CVE-2017-15906 [MEDIUM] CWE-20 openssh: Improper write operations in readonly mode allow for zero-length file creation
openssh: Improper write operations in readonly mode allow for zero-length file creation
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Package: openssh (Red Hat Enterprise Linux 5) - Not affected
Package: openssh (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2017-15906: openssh - The process_open function in sftp-server.c in OpenSSH before 7.6 does not proper...
vendor_debian·2017·CVSS 5.3
CVE-2017-15906 [MEDIUM] CVE-2017-15906: openssh - The process_open function in sftp-server.c in OpenSSH before 7.6 does not proper...
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Scope: local
bookworm: resolved (fixed in 1:7.6p1-1)
bullseye: resolved (fixed in 1:7.6p1-1)
forky: resolved (fixed in 1:7.6p1-1)
sid: resolved (fixed in 1:7.6p1-1)
trixie: resolved (fixed in 1:7.6p1-1)
No detection rules found.
No public exploits indexed.
arXiv
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
arxiv_fulltext·2021-03-26
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
Understanding Internet of Things Malware by Analyzing Endpoints in their Static Artifacts
Afsah Anwar^1, Jinchun Choi^1,2, Abdulrahman Alabduljabbar^1, Hisham Alasmary^1,3,
Jeffrey Spaulding^4, An Wang^5, Songqing Chen^6, DaeHun Nyang^7, Amro Awad^8, and David Mohaisen^1
^1 University of Central Florida
2mm^2 Texas A&M University 2mm^3 King Khalid University 2mm^4 Canisius College
2mm^5 Case Western Reserve University
2mm^6 GMU 2mm^7 Ewha Womans University 2mm^8 NCSU
## Abstract
The lack of security measures among the Internet of Things (IoT) devices and their persistent online connection gives adversaries a prime opportunity to target them or even abuse them as intermediary targets in larger attacks such as distributed denial-of-service (DDoS) campaigns. In this paper, we analyze IoT m
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
2019/10/29
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in und
Trendmicro
Current and Future Attacks Threatening Esports
blogs_trendmicro·2019-10-29
Current and Future Attacks Threatening Esports
Cyber Crime
# Current and Future Attacks Threatening Esports
Cybercriminals will increasingly target the esports industry over the next three years. Many underground forums already have sections dedicated to gaming or esports sales, and the goods and services offered in these forums generate a lot of interest.
By: Mayra Rosario Fuentes, Fernando Merces
Oct 29, 2019
Read time: ( words)
Save to Folio
Esports has evolved from niche entertainment into a highly lucrative industry. Growing ad revenue and sponsorships allow the tournaments to grow; and as the tournaments grow, the prize pool grows as well. Of course, growing popularity and increased funds open up the entities involved to cybercriminals looking for any opportunity to make a profit.
Cheats and hacks are widely available in u
Bugzilla
CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation [fedora-all]
bugzilla·2017-10-26·CVSS 5.3
CVE-2017-15906 [MEDIUM] CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation [fedora-all]
CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this iss
Bugzilla
CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation
bugzilla·2017-10-26·CVSS 5.3
CVE-2017-15906 [MEDIUM] CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation
CVE-2017-15906 openssh: Improper write operations in readonly mode allow for zero-length file creation
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.
Upstream patch:
https://github.com/openbsd/src/commit/a6981567e8e215acc1ef690c8dbb30f2d9b00a19
References:
https://www.openssh.com/txt/release-7.6
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1506631]
---
Analysis:
It seems the maximum impact of this flaw is that the attacker can create an extremely large number of zero length files to fill up a harddisk on a remote server which the attacker has read-only access to.
---
This issue has been addressed in the followi
http://www.securityfocus.com/bid/101552https://access.redhat.com/errata/RHSA-2018:0980https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://github.com/openbsd/src/commit/a6981567e8e215acc1ef690c8dbb30f2d9b00a19https://lists.debian.org/debian-lts-announce/2018/09/msg00010.htmlhttps://security.gentoo.org/glsa/201801-05https://security.netapp.com/advisory/ntap-20180423-0004/https://www.openssh.com/txt/release-7.6https://www.oracle.com/security-alerts/cpujan2020.htmlhttp://www.securityfocus.com/bid/101552https://access.redhat.com/errata/RHSA-2018:0980https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://github.com/openbsd/src/commit/a6981567e8e215acc1ef690c8dbb30f2d9b00a19https://lists.debian.org/debian-lts-announce/2018/09/msg00010.htmlhttps://security.gentoo.org/glsa/201801-05https://security.netapp.com/advisory/ntap-20180423-0004/https://www.openssh.com/txt/release-7.6https://www.oracle.com/security-alerts/cpujan2020.html
2017-10-26
Published