cbcvebase.
CVE-2019-14889
published 2019-12-10

CVE-2019-14889: A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp…

PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.16%
86.5th percentile
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.

Affected

18 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlibssh< libssh 0.9.3-1 (bookworm)libssh 0.9.3-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
libsshlibssh< 0.8.80.8.8
libsshlibssh>= 0 < 0.9.3-10.9.3-1
libsshlibssh>= 0 < 0.9.3-10.9.3-1
libsshlibssh>= 0 < 0.9.3-10.9.3-1
libsshlibssh>= 0 < 0.9.3-10.9.3-1
libsshlibssh>= 0.9.0 < 0.9.30.9.3
opensuseleap
oraclemysql_workbench<= 8.0.19
red_hatlibssh
red_hatlibssh

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_oracle8.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.