CVE-2019-14889
published 2019-12-10CVE-2019-14889: A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
3.16%
86.5th percentile
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libssh | < libssh 0.9.3-1 (bookworm) | libssh 0.9.3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libssh | libssh | < 0.8.8 | 0.8.8 |
| libssh | libssh | >= 0 < 0.9.3-1 | 0.9.3-1 |
| libssh | libssh | >= 0 < 0.9.3-1 | 0.9.3-1 |
| libssh | libssh | >= 0 < 0.9.3-1 | 0.9.3-1 |
| libssh | libssh | >= 0 < 0.9.3-1 | 0.9.3-1 |
| libssh | libssh | >= 0.9.0 < 0.9.3 | 0.9.3 |
| opensuse | leap | — | — |
| oracle | mysql_workbench | <= 8.0.19 | — |
| red_hat | libssh | — | — |
| red_hat | libssh | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.07.1HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_oracle8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) — CVE-2019-14889
vendor_oracle·2020-04-15·CVSS 8.0
CVE-2019-14889 [HIGH] Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) — CVE-2019-14889
Oracle Oracle MySQL Risk Matrix: MySQL Workbench (libssh) vulnerability
CVE: CVE-2019-14889
CVSS: 8.0
Protocol: MySQL Workbench
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Ubuntu
libssh vulnerability
vendor_ubuntu·2019-12-10
CVE-2019-14889 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could be made to run programs under certain conditions.
It was discovered that libssh incorrectly handled certain scp commands. If
a user or automated system were tricked into using a specially-crafted scp
command, a remote attacker could execute arbitrary commands on the server.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libssh: unsanitized location in scp could lead to unwanted command execution
vendor_redhat·2019-12-05·CVSS 8.8
CVE-2019-14889 [HIGH] CWE-78 libssh: unsanitized location in scp could lead to unwanted command execution
libssh: unsanitized location in scp could lead to unwanted command execution
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
A flaw was found with the libssh API function ssh_scp_new(). A user able to connect to a server using SCP could execute arbitrary command using a user-provided path, leading to a compromise of the remote target.
Statement: Red Hat Virtualization only uses libssh fo
Debian
CVE-2019-14889: libssh - A flaw was found with the libssh API function ssh_scp_new() in versions before 0...
vendor_debian·2019·CVSS 8.8
CVE-2019-14889 [HIGH] CVE-2019-14889: libssh - A flaw was found with the libssh API function ssh_scp_new() in versions before 0...
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
Scope: local
bookworm: resolved (fixed in 0.9.3-1)
bullseye: resolved (fixed in 0.9.3-1)
forky: resolved (fixed in 0.9.3-1)
sid: resolved (fixed in 0.9.3-1)
trixie: resolved (fixed in 0.9.3-1)
GHSA
GHSA-mrxf-x73j-79wm: A flaw was found with the libssh API function ssh_scp_new() in versions before 0
ghsa_unreviewed·2022-05-24
CVE-2019-14889 [HIGH] CWE-78 GHSA-mrxf-x73j-79wm: A flaw was found with the libssh API function ssh_scp_new() in versions before 0
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
OSV
CVE-2019-14889: A flaw was found with the libssh API function ssh_scp_new() in versions before 0
osv·2019-12-10·CVSS 8.8
CVE-2019-14889 [HIGH] CVE-2019-14889: A flaw was found with the libssh API function ssh_scp_new() in versions before 0
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [fedora-all]
bugzilla·2019-12-10·CVSS 8.8
CVE-2019-14889 [HIGH] CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [fedora-all]
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [epel-all]
bugzilla·2019-12-10·CVSS 8.8
CVE-2019-14889 [HIGH] CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [epel-all]
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mult
Bugzilla
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution
bugzilla·2019-11-14·CVSS 8.8
CVE-2019-14889 [HIGH] CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution
CVE-2019-14889 libssh: unsanitized location in scp could lead to unwanted command execution
When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of ssh_scp_new(), it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
Discussion:
Upstream bug: https://bugs.libssh.org/T181
---
Acknowledgments:
Name: libssh project
Upstream: Cure53
---
External References:
https://www.libssh.org/security/advisories/CVE-2019-14889.txt
---
Created libssh tracking bugs for this issue:
Affects: epel-all [bug 1781781]
Affects: fedora-all [bug 1781780]
---
Upstream patchset:
h
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14889https://lists.debian.org/debian-lts-announce/2019/12/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JJWJTXVWLLJTVHBPGWL7472S5FWXYQR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EV2ONSPDJCTDVORCB4UGRQUZQQ46JHRN/https://security.gentoo.org/glsa/202003-27https://usn.ubuntu.com/4219-1/https://www.libssh.org/security/advisories/CVE-2019-14889.txthttps://www.oracle.com/security-alerts/cpuapr2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14889https://lists.debian.org/debian-lts-announce/2019/12/msg00020.htmlhttps://lists.debian.org/debian-lts-announce/2023/05/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JJWJTXVWLLJTVHBPGWL7472S5FWXYQR/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EV2ONSPDJCTDVORCB4UGRQUZQQ46JHRN/https://security.gentoo.org/glsa/202003-27https://usn.ubuntu.com/4219-1/https://www.libssh.org/security/advisories/CVE-2019-14889.txthttps://www.oracle.com/security-alerts/cpuapr2020.html
2019-12-10
Published