ALPINE-CVE-2019-6109 PUBLISHED CVSS 6.800000190734863 MEDIUM

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

Risk Scores

CVSS v3.1
6.800000190734863
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
Alpine:v3.10openssh5.1p1-r0, 5.1_p1-r2, 5.1_p1-r1
Alpine:v3.18openssh*, 6.2_p2-r0, 6.2_p2-r1
Alpine:v3.6openssh6.6_p1-r5, 6.6_p1-r6, 6.7_p1-r0
Alpine:v3.23openssh7.9, 7.9, 7.9
Alpine:v3.19openssh5.1, 0, 5.1_p1-r1
Alpine:v3.16openssh5.2_p1-r2, 5.2_p1-r3, 5.3_p1-r3
Alpine:v3.13openssh5.3_p1-r3, 5.2_p1-r3, 5.2_p1-r2
Alpine:v3.17openssh5.2_p1-r2, 5.2_p1-r3, 5.3_p1-r3
Alpine:v3.14openssh7.5_p1-r5, 0, 5.1_p1-r1
Alpine:v3.8openssh*, *, *
Alpine:v3.20openssh5.8, 5.8, 5.8
Alpine:v3.7openssh7.5_p1-r7, 7.5_p1-r8, 7.5_p1-r9
Alpine:v3.11openssh5.5_p1-r3, 5.8_p1-r3, 5.8_p2-r3
Alpine:v3.9openssh7.5_p1-r4, 7.5_p1-r3, 7.5_p1-r2
Alpine:v3.12openssh*, 7.9, 7.9
Alpine:v3.21openssh7.1_p2-r0, 7.2_p1-r0, 7.2_p2-r0
Alpine:v3.15openssh7.9, 0, 5.1_p1-r1
Alpine:v3.22openssh7.1_p2-r0, 7.2_p1-r0, 7.2_p2-r0

Timeline

References

Open in Interactive Console →