CVE-2019-14889

Source
https://nvd.nist.gov/vuln/detail/CVE-2019-14889
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14889.json
Related
Published
2019-12-10T23:15:10Z
Modified
2023-11-29T07:07:13.659364Z
Details

A flaw was found with the libssh API function sshscpnew() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.

References

Affected packages

Alpine:v3.10 / libssh

Package

Name
libssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.8.8-r0

Affected versions

0.*

0.4.5-r0
0.4.6-r0
0.4.8-r0
0.5.0-r0
0.5.1-r0
0.5.2-r0
0.5.2-r1
0.5.3-r0
0.5.4-r0
0.5.5-r0
0.6.0-r0
0.6.3-r0
0.6.4-r0
0.6.5-r0
0.7.0-r0
0.7.1-r0
0.7.2-r0
0.7.3-r0
0.7.3-r1
0.7.4-r0
0.7.5-r0
0.7.5-r1
0.7.5-r2
0.7.5-r3
0.7.6-r0
0.7.6-r1

Alpine:v3.11 / libssh

Package

Name
libssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.9.3-r0

Affected versions

0.*

0.4.5-r0
0.4.6-r0
0.4.8-r0
0.5.0-r0
0.5.1-r0
0.5.2-r0
0.5.2-r1
0.5.3-r0
0.5.4-r0
0.5.5-r0
0.6.0-r0
0.6.3-r0
0.6.4-r0
0.6.5-r0
0.7.0-r0
0.7.1-r0
0.7.2-r0
0.7.3-r0
0.7.3-r1
0.7.4-r0
0.7.5-r0
0.7.5-r1
0.7.5-r2
0.7.5-r3
0.7.6-r0
0.7.6-r1
0.8.7-r1
0.9.0-r1
0.9.2-r1

Alpine:v3.8 / libssh

Package

Name
libssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.7.6-r1

Affected versions

0.*

0.4.5-r0
0.4.6-r0
0.4.8-r0
0.5.0-r0
0.5.1-r0
0.5.2-r0
0.5.2-r1
0.5.3-r0
0.5.4-r0
0.5.5-r0
0.6.0-r0
0.6.3-r0
0.6.4-r0
0.6.5-r0
0.7.0-r0
0.7.1-r0
0.7.2-r0
0.7.3-r0
0.7.3-r1
0.7.4-r0
0.7.5-r0
0.7.5-r1
0.7.5-r2
0.7.5-r3

Alpine:v3.9 / libssh

Package

Name
libssh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.7.6-r2

Affected versions

0.*

0.4.5-r0
0.4.6-r0
0.4.8-r0
0.5.0-r0
0.5.1-r0
0.5.2-r0
0.5.2-r1
0.5.3-r0
0.5.4-r0
0.5.5-r0
0.6.0-r0
0.6.3-r0
0.6.4-r0
0.6.5-r0
0.7.0-r0
0.7.1-r0
0.7.2-r0
0.7.3-r0
0.7.3-r1
0.7.4-r0
0.7.5-r0
0.7.5-r1
0.7.5-r2
0.7.5-r3

Git / git.libssh.org/projects/libssh.git

Affected ranges

Type
GIT
Repo
https://git.libssh.org/projects/libssh.git
Events
Fixed
7850307210590a9a1b03ab0273d29b3926a974c5
Introduced
79900e5246da9a1712d8822a53aaf5fd0abc6f40