CVE-2019-6110

SOURCE - nist

Summary

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

EPSS Score: 0.00425 (0.742)

Common Weakness Enumeration (CWE)

SOURCE - nist

Inappropriate Encoding for Output Context

SOURCE - redhat

User Interface (UI) Misrepresentation of Critical Information


debian

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

N/Alow
PackageTypeOS NameOS VersionAffected RangesFix Versions
debian/opensshdebdebian12>=1:9.2p1-2+deb12u2Not yet available
debian/opensshdebdebianunstable>=1:9.7p1-5Not yet available
debian/opensshdebdebian10>=1:7.9p1-10+deb10u2Not yet available
debian/opensshdebdebian11>=1:8.4p1-5+deb11u3Not yet available
debian/opensshdebdebian13>=1:9.7p1-5Not yet available

Severity and metrics

No CVSS data available from this source.

nist

CREATED


UPDATED



EXPLOITABILITY SCORE

1.6


EXPLOITS FOUND

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

6.8medium

ubuntu

CREATED


UPDATED



EXPLOITABILITY SCORE

1.6


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

6.8low

redhat

CREATED


UPDATED



EXPLOITABILITY SCORE

1.6


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)

CVSS SCORE

3.1low

suse

CREATED


UPDATED



EXPLOITABILITY SCORE

2.1


EXPLOITS FOUND
-

COMMON WEAKNESS ENUMERATION (CWE)-

CVSS SCORE

4.6medium

inthewild

CREATED


UPDATED



EXPLOITABILITY SCORE

-


EXPLOITS FOUND

-


COMMON WEAKNESS ENUMERATION (CWE)-
RATING UNAVAILABLE FROM SOURCE