CyberSec.Space Logo
Back to CVE Browser

CVE-2019-14889

HIGH
8.8
CVSS Severity Score
EPSS Score0.0860%
EPSS Percentile12.58th
PublishedDec 10, 2019
Last ModifiedNov 21, 2024

Vulnerability Description

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.

Affected Platforms (CPE)

πŸ“¦
Libssh

Libssh

< 0.8.8
πŸ“¦
Libssh

Libssh

>= 0.9.0 and < 0.9.3
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ’»
Canonical

Ubuntu Linux

= 19.04
πŸ’»
Canonical

Ubuntu Linux

= 19.10
πŸ’»
Opensuse

Leap

= 15.1
πŸ’»
Fedoraproject

Fedora

= 30
πŸ’»
Fedoraproject

Fedora

= 31
πŸ’»
Debian

Debian Linux

= 8.0
πŸ“¦
Oracle

Mysql Workbench

<= 8.0.19

References & Advisories

Related Vulnerabilities