CVE-2019-6111

Publication date 14 January 2019

Last updated 11 February 2025


Ubuntu priority

Cvss 3 Severity Score

5.9 · Medium

Score breakdown

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the scp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the scp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file).

Read the notes from the security team

Status

Package Ubuntu Release Status
openssh 24.10 oracular
Not affected
24.04 LTS noble
Not affected
23.10 mantic
Not affected
23.04 lunar
Not affected
22.10 kinetic
Not affected
22.04 LTS jammy FIPS Updates FIPS compliant package with security fixes. Available with Ubuntu Pro.
Not affected
21.10 impish
Not affected
21.04 hirsute
Not affected
20.10 groovy
Not affected
20.04 LTS focal FIPS FIPS certified package. Available with Ubuntu Pro.
Not affected
19.10 eoan
Not affected
19.04 disco
Not affected
18.10 cosmic
Fixed 1:7.7p1-4ubuntu0.3
18.04 LTS bionic
Fixed 1:7.6p1-4ubuntu0.3
16.04 LTS xenial
Fixed 1:7.2p2-4ubuntu2.8
14.04 LTS trusty
Fixed 1:6.6p1-2ubuntu2.13
openssh-ssh1 24.10 oracular Ignored
24.04 LTS noble Ignored
23.10 mantic Ignored end of life, was needs-triage
23.04 lunar Ignored end of life, was needs-triage
22.10 kinetic Ignored end of life, was needs-triage
22.04 LTS jammy Ignored
21.10 impish Ignored end of life
21.04 hirsute Ignored end of life
20.10 groovy Ignored end of life
20.04 LTS focal Ignored
19.10 eoan Ignored end of life
19.04 disco Ignored end of life
18.10 cosmic Ignored end of life
18.04 LTS bionic Ignored
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Notes


mdeslaur

openssh-ssh1 is only provided for compatibility with old devices that cannot be upgraded to modern protocols. We will not be providing any security support for the openssh-ssh1 package as it is insecure and should be used in trusted environments only. The recommended workaround for this issue is to switch to using sftp instead of scp. The updates in USN-3885-1 inverted two CVE numbers by accident. The initial USN was incomplete and did not include the second commit.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
openssh

Severity score breakdown

Parameter Value
Base score 5.9 · Medium
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact High
Availability impact None
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N