In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-01-10T00:00:00

Updated: 2022-12-13T00:00:00

Reserved: 2019-01-10T00:00:00


Link: CVE-2018-20685

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-01-10T21:29:00.377

Modified: 2023-02-23T23:15:18.260


Link: CVE-2018-20685

JSON object: View

cve-icon Redhat Information

No data.

CWE