scp in OpenSSH 4.2p1 allows attackers to execute arbitrary commands via filenames that contain shell metacharacters or spaces, which are expanded twice.
CVSS Details
- CVSS 3.1 Base Score: 9.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Upgrade macOS to the latest versionApply OS X security update 2007-003 | Dec 16, 2011 | Jan 25, 2006 |
| Debian | — | Upgrade opensshUpgrade dropbear | Jul 30, 2024 | Jan 25, 2006 |
| Gentoo Linux | — | Upgrade net-misc/openssh.Upgrade net-misc/dropbear. | Oct 30, 2017 | Jan 25, 2006 |
| Suse | — | Upgrade openssh-fipsUpgrade openssh-clientsUpgrade openssh-openssl1-helpersUpgrade opensshUpgrade openssh-helpersUpgrade openssh-serverUpgrade openssh-server-config-rootloginUpgrade openssh-askpassUpgrade openssh-commonUpgrade openssh-openssl1Upgrade openssh-cavs | Feb 17, 2015 | Jun 27, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub