The scp client in OpenSSH 8.2 incorrectly sends duplicate responses to the server upon a utimes system call failure, which allows a malicious unprivileged user on the remote server to overwrite arbitrary files in the client's download directory by creating a crafted subdirectory anywhere on the remote server. The victim must use the command scp -rp to download a file hierarchy containing, anywhere inside, this crafted subdirectory. NOTE: the vendor points out that "this attack can achieve no more than a hostile peer is already able to achieve within the scp protocol" and "utimes does not fail under normal circumstances.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade openssh | Jul 30, 2024 | Jun 1, 2020 |
| Huawei Euleros 2_0_sp2 | — | Upgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-serverUpgrade opensshUpgrade openssh-askpass | Nov 3, 2020 | Jun 1, 2020 |
| Huawei Euleros 2_0_sp3 | — | Upgrade openssh-keycatUpgrade openssh-clientsUpgrade opensshUpgrade openssh-serverUpgrade openssh-askpass | Sep 28, 2020 | Jun 1, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-askpassUpgrade openssh-serverUpgrade openssh | Sep 3, 2020 | Jun 1, 2020 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssh-ldapUpgrade openssh-cavsUpgrade openssh-serverUpgrade openssh-keycatUpgrade openssh-clientsUpgrade openssh-askpassUpgrade openssh | Jul 31, 2020 | Jun 1, 2020 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Jun 8, 2020 | Jun 1, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 1, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub