---
title: "CVE-2019-6111\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-6111?format=md
keywords: index, follow
---

# CVE-2019-6111

Publication date 14 January 2019

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-6111?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in OpenSSH 7.9. Due to the scp implementation being
derived from 1983 rcp, the server chooses which files/directories are sent
to the client. However, the scp client only performs cursory validation of
the object name returned (only directory traversal attacks are prevented).
A malicious scp server (or Man-in-The-Middle attacker) can overwrite
arbitrary files in the scp client target directory. If recursive operation
(-r) is performed, the server can manipulate subdirectories as well (for
example, to overwrite the .ssh/authorized\_keys file).

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-6111?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| openssh | 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Not affected |
| 18.10 cosmic | Fixed 1:7.7p1-4ubuntu0.3 |
| 18.04 LTS bionic | Fixed 1:7.6p1-4ubuntu0.3 |
| 16.04 LTS xenial | Fixed 1:7.2p2-4ubuntu2.8 |
| 14.04 LTS trusty | Fixed 1:6.6p1-2ubuntu2.13 |
| openssh-ssh1 | 24.10 oracular | Ignored |
| 24.04 LTS noble | Ignored |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Ignored |
| 21.10 impish | Ignored end of life |
| 21.04 hirsute | Ignored end of life |
| 20.10 groovy | Ignored end of life |
| 20.04 LTS focal | Ignored |
| 19.10 eoan | Ignored end of life |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Ignored end of standard support, was needs-triage |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-6111?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

openssh-ssh1 is only provided for compatibility with old devices
that cannot be upgraded to modern protocols. We will not be
providing any security support for the openssh-ssh1 package as
it is insecure and should be used in trusted environments only.
The recommended workaround for this issue is to switch to using
sftp instead of scp.
The updates in USN-3885-1 inverted two CVE numbers by accident.
The initial USN was incomplete and did not include the second
commit.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| openssh | * Upstream:   [391ffc4](https://github.com/openssh/openssh-portable/commit/391ffc4b9d31fa1f4ad566499fef9176ff8a07dc) * Upstream:   [3d896c1](https://github.com/openssh/openssh-portable/commit/3d896c157c722bc47adca51a58dca859225b5874) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-6111)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-6111)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-6111)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-6111)

### Related Ubuntu Security Notices (USN)

+ [USN-3885-1](https://usn.ubuntu.com/USN-3885-1)
+ OpenSSH vulnerabilities
+ 7 February 2019

+ [USN-3885-2](https://usn.ubuntu.com/USN-3885-2)
+ OpenSSH vulnerability
+ 4 March 2019

### Other references

* <https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt>
* <https://lists.mindrot.org/pipermail/openssh-unix-dev/2019-January/037459.html>
* <https://www.cve.org/CVERecord?id=CVE-2019-6111>
