VDB

CVE-2019-6110

CVE-2019-6110 PUBLISHED

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

EPSS 20.91% · 97.3th percentile

Risk Scores

EPSS Score
20.91%
97.3th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSopenssh1:7.6p1-4ubuntu0.7+esm1, 1:7.6p1-4ubuntu0.7, 1:7.6p1-4ubuntu0.6
Ubuntu:18.04:LTSopenssh-ssh10, 1:7.5p1-9, 1:7.5p1-10
Ubuntu:20.04:LTSopenssh1:8.1p1-5, *, 1:8.2p1-4ubuntu0.13
Ubuntu:Pro:16.04:LTSopenssh*, 1:6.9p1-2, 1:6.9p1-3
Ubuntu:20.04:LTSopenssh-ssh1*, 0
Ubuntu:Pro:14.04:LTSopenssh*, *, *

Timeline

  • Jan 15, 2019 CVE Published
  • Jan 20, 2019 PoC Published
  • Mar 8, 2019 PoC Published
  • Oct 2, 2020 PoC Published
  • Nov 6, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Sep 6, 2021 PoC Published
  • Dec 14, 2022 EPSS Score
  • Oct 9, 2024 PoC Published
  • Dec 12, 2024 PoC Published
  • Mar 17, 2025 EPSS Score
  • Mar 28, 2025 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›