CVE-2019-6109
published 2019-01-31CVE-2019-6109: An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can…
PriorityP184medium6.8CVSS 3.1
AVNACHPRNUIRSUCHIHAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
3.81%
88.9th percentile
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | openssh | < openssh 1:7.9p1-6 (bookworm) | openssh 1:7.9p1-6 (bookworm) |
| fedoraproject | fedora | — | — |
| fujitsu | m10-1_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-1_firmware | < xcp3070 | xcp3070 |
| fujitsu | m10-4_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-4_firmware | < xcp3070 | xcp3070 |
| fujitsu | m10-4s_firmware | < xcp2361 | xcp2361 |
| fujitsu | m10-4s_firmware | < xcp3070 | xcp3070 |
| fujitsu | m12-1_firmware | < xcp2361 | xcp2361 |
| fujitsu | m12-1_firmware | < xcp3070 | xcp3070 |
| fujitsu | m12-2_firmware | < xcp2361 | xcp2361 |
| fujitsu | m12-2_firmware | < xcp3070 | xcp3070 |
| fujitsu | m12-2s_firmware | < xcp2361 | xcp2361 |
| fujitsu | m12-2s_firmware | < xcp3070 | xcp3070 |
| openbsd | openssh | <= 7.9 | — |
| openbsd | openssh | >= 0 < 1:7.9p1-6 | 1:7.9p1-6 |
| openbsd | openssh | >= 0 < 1:7.9p1-6 | 1:7.9p1-6 |
| openbsd | openssh | >= 0 < 1:7.9p1-6 | 1:7.9p1-6 |
| openbsd | openssh | >= 0 < 1:7.9p1-6 | 1:7.9p1-6 |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack vector is crafted object/file names containing ANSI control codes sent by a malicious or MitM SSH server to manipulate the scp client's progress display output, hiding additional files being transferred. ↗
- →The vulnerable code path is specifically in the refresh_progress_meter() function within progressmeter.c of the scp client. Focus dynamic analysis and code auditing on this function for missing character/ANSI encoding sanitization. ↗
- →Only the scp binary (part of openssh-clients package) is affected, not the SSH protocol or ssh client itself. Detection should focus on scp sessions to untrusted or newly-keyed servers. ↗
- →A change in the SSH host key of the server being connected to via scp can be an indicator of a MitM attack exploiting this vulnerability. Monitor for host key change warnings during scp sessions. ↗
- ·On Debian-based systems, the vulnerability is resolved in openssh package version 1:7.9p1-6. Ensure deployed versions meet or exceed this. ↗
- ·Red Hat Enterprise Linux 7 has marked this as 'Will not fix'. Operators on RHEL 7 should consider mitigating by removing the openssh-clients package if scp is not required. ↗
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:N
osv6.8MEDIUM
vulncheck6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2pqm-q853-jfvf: An issue was discovered in OpenSSH 7
ghsa_unreviewed·2022-05-13
CVE-2019-6109 [MEDIUM] CWE-116 GHSA-2pqm-q853-jfvf: An issue was discovered in OpenSSH 7
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
OSV
CVE-2019-6109: An issue was discovered in OpenSSH 7
osv·2019-01-31·CVSS 6.8
CVE-2019-6109 [MEDIUM] CVE-2019-6109: An issue was discovered in OpenSSH 7
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
VulnCheck
OpenBSD openssh Improper Encoding or Escaping of Output
vulncheck·2019·CVSS 6.8
CVE-2019-6109 [MEDIUM] OpenBSD openssh Improper Encoding or Escaping of Output
OpenBSD openssh Improper Encoding or Escaping of Output
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Affected: OpenBSD openssh
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://cybersecurityworks.com/blog/cyber-risk/how-safe-are-enterprise-data-storage-systems.html; https://cybersecurityworks.com/blog/ransomware
Palo Alto
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
vendor_paloalto·2024-04-05·CVSS 4.3
CVE-2007-2768 [MEDIUM] PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Prisma SD-WAN ION. While Prisma SD-WAN ION may include the
CVEs: CVE-2007-2768, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-20012, CVE-2016-8858, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2021-41617, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-28531, CVE-2023-38408, CVE-2023-51384, CVE-2023-51385, CVE-2023-51767
Affected products: Prisma SD
CISA ICS
Siemens SCALANCE X-200RNA Switch Devices
cisa_ics·2022-12-19
Siemens SCALANCE X-200RNA Switch Devices
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SCALANCE X-200RNA Switch Devices
Last RevisedDecember 19, 2022
Alert CodeICSA-22-349-21
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available
- Vendor: Siemens
- Equipment: SCALANCE X-200RNA switch devices before V3.2.7
- Vulnerabilities: Observable Timing Discrepancy; Race Condition; Improper Restriction of Operations within the Bounds of a Memory Buffer; Improper Input Validation; NULL Pointer Dereference; Use After Free; Cryptographic Issues; Comparison of Incompatible Types; Resource Management
Palo Alto
PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
vendor_paloalto·2020-04-08·CVSS 5.3
[MEDIUM] CWE-20 PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
PAN-SA-2020-0002 PAN-OS: OpenSSH software upgraded to resolve multiple vulnerabilities
OpenSSH software included with PAN-OS has been upgraded to resolve multiple vulnerabilities. These issue affects Palo Alto Networks PAN-OS 7.1 versions before 7.1.26; 8.1 versions before 8.1.13; 9.0 versions before 9.0.7. PAN-OS 8.0 is now end-of-life as of October 31, 2019, and is no longer covered by our Product Security Assurance policies. The resolved vulnerabilities include: CVE CVSS Summary CVE-2018-20685 5.3 ( CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N ) In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. CVE-2019-61
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2019-02-07
CVE-2018-20685 OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
Harry Sintonen discovered multiple issues in the OpenSSH scp utility. If a
user or automated system were tricked into connecting to an untrusted
server, a remote attacker could possibly use these issues to write to
arbitrary files, change directory permissions, and spoof client output.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2019-6109: openssh - An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the...
vendor_debian·2019·CVSS 6.8
CVE-2019-6109 [MEDIUM] CVE-2019-6109: openssh - An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the...
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Scope: local
bookworm: resolved (fixed in 1:7.9p1-6)
bullseye: resolved (fixed in 1:7.9p1-6)
forky: resolved (fixed in 1:7.9p1-6)
sid: resolved (fixed in 1:7.9p1-6)
trixie: resolved (fixed in 1:7.9p1-6)
Red Hat
openssh: Missing character encoding in progress display allows for spoofing of scp client output
vendor_redhat·2018-11-16·CVSS 6.8
CVE-2019-6109 [MEDIUM] CWE-451 openssh: Missing character encoding in progress display allows for spoofing of scp client output
openssh: Missing character encoding in progress display allows for spoofing of scp client output
An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.
Statement: This issue affects the scp client shipped with openssh. The SSH protocol or the SSH client is not affected. For more detailed analysis please refer to: https://bugzilla.redhat.com/show_bug.cgi?id=1666119#c3
Mitigation: This issue only affects the users of scp binary which is a part of openssh-clients package. Other usage of SSH protocol
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output [fedora-all]
bugzilla·2019-01-15·CVSS 6.8
CVE-2019-6109 [MEDIUM] CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output [fedora-all]
CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2019-6110 openssh: Acceptance and display of arbitrary stderr allows for spoofing of scp client output
bugzilla·2019-01-15·CVSS 6.8
CVE-2019-6110 [MEDIUM] CVE-2019-6110 openssh: Acceptance and display of arbitrary stderr allows for spoofing of scp client output
CVE-2019-6110 openssh: Acceptance and display of arbitrary stderr allows for spoofing of scp client output
OpenSSH has a vulnerability in the scp client utility. Due to accepting and displaying arbitrary stderr output from the scp server, a malicious server can manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.
External Reference:
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
Proposed Patch:
https://sintonen.fi/advisories/scp-name-validator.patch
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1666125]
---
Analysis:
This is a flaw in the scp client (/usr/bin/scp) shipped as a part of openssh-clients package. The flaw exists in the way scp clients accept and displ
Bugzilla
CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output
bugzilla·2019-01-15·CVSS 6.8
CVE-2019-6109 [MEDIUM] CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output
CVE-2019-6109 openssh: Missing character encoding in progress display allows for spoofing of scp client output
OpenSSH has a vulnerability in the scp client utility. Due to missing character encoding in the progress display, the object name can be used to manipulate the client output, for example to employ ANSI codes to hide additional files being transferred.
External Reference:
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
Proposed Patch:
https://sintonen.fi/advisories/scp-name-validator.patch
Discussion:
Created openssh tracking bugs for this issue:
Affects: fedora-all [bug 1666121]
---
There was a patch sanitizing the encoding of the filenames in the progress meter, but the upstream bugzilla is down so I can not find it. I would rather see fixed it
http://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.htmlhttps://access.redhat.com/errata/RHSA-2019:3702https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.chttps://cvsweb.openbsd.org/src/usr.bin/ssh/scp.chttps://lists.debian.org/debian-lts-announce/2019/03/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W3YVQ2BPTOVDCFDVNC2GGF5P5ISFG37G/https://security.gentoo.org/glsa/201903-16https://security.netapp.com/advisory/ntap-20190213-0001/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txthttps://usn.ubuntu.com/3885-1/https://www.debian.org/security/2019/dsa-4387https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-06/msg00058.htmlhttps://access.redhat.com/errata/RHSA-2019:3702https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdfhttps://cvsweb.openbsd.org/src/usr.bin/ssh/progressmeter.chttps://cvsweb.openbsd.org/src/usr.bin/ssh/scp.chttps://lists.debian.org/debian-lts-announce/2019/03/msg00030.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W3YVQ2BPTOVDCFDVNC2GGF5P5ISFG37G/https://security.gentoo.org/glsa/201903-16https://security.netapp.com/advisory/ntap-20190213-0001/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txthttps://usn.ubuntu.com/3885-1/https://www.debian.org/security/2019/dsa-4387https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-01-31
Published
Exploited in the wild