Bug 1121821 (CVE-2019-6111)

Summary: VUL-0: CVE-2019-6111: openssh,openssh-openssl1: scp client missing received object name validation
Product: [Novell Products] SUSE Security Incidents Reporter: Karol Babioch <karol>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Major    
Priority: P3 - Medium CC: atoptsoglou, jjindrak, jkohoutek, meissner, peter.simons, pmonrealgonzalez, smash_bz, vcizek
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/222746/
See Also: http://bugzilla.suse.com/show_bug.cgi?id=1123028
Whiteboard: CVSSv2:NVD:CVE-2019-6111:5.8:(AV:N/AC:M/Au:N/C:N/I:P/A:P) CVSSv3:NVD:CVE-2019-6111:5.9:(AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N) CVSSv3:RedHat:CVE-2019-6111:5.3:(AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N) CVSSv3:SUSE:CVE-2019-6111:4.8:(AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N) maint:released:sle10-sp3:64249
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Deadline: 2019-04-08   

Description Karol Babioch 2019-01-14 10:43:34 UTC
CVE-2019-6111

2. CWE-20: scp client missing received object name validation [CVE-2019-6111]

Due to the scp implementation being derived from 1983 rcp [1], the server chooses which
files/directories are sent to the client. However, scp client only perform cursory
validation of the object name returned (only directory traversal attacks are prevented).
A malicious scp server can overwrite arbitrary files in the scp client target directory.
If recursive operation (-r) is performed, the server can manipulate subdirectories
as well (for example overwrite .ssh/authorized_keys).

The same vulnerability in WinSCP is known as CVE-2018-20684.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-6111
http://seclists.org/oss-sec/2019/q1/63
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
https://sintonen.fi/advisories/scp-name-validator.patch
Comment 1 Pedro Monreal Gonzalez 2019-01-15 13:23:53 UTC
I would wait for upstream to review the patch for CVE-2019-6109, CVE-2019-6110 and CVE-2019-6109.
Comment 6 Swamp Workflow Management 2019-01-18 17:12:36 UTC
SUSE-SU-2019:0125-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1
SUSE Linux Enterprise Server 12-LTSS (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1
Comment 7 Swamp Workflow Management 2019-01-18 17:15:44 UTC
SUSE-SU-2019:0126-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Module for Server Applications 15 (src):    openssh-7.6p1-9.13.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    openssh-7.6p1-9.13.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    openssh-askpass-gnome-7.6p1-9.13.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    openssh-7.6p1-9.13.1
Comment 8 Swamp Workflow Management 2019-01-18 20:10:23 UTC
SUSE-SU-2019:13931-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    openssh-6.6p1-36.12.1, openssh-askpass-gnome-6.6p1-36.12.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    openssh-6.6p1-36.12.1, openssh-askpass-gnome-6.6p1-36.12.1
Comment 9 Swamp Workflow Management 2019-01-21 14:13:14 UTC
SUSE-SU-2019:0132-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE OpenStack Cloud 7 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP3 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Enterprise Storage 4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE CaaS Platform ALL (src):    openssh-7.2p2-74.35.1
SUSE CaaS Platform 3.0 (src):    openssh-7.2p2-74.35.1
OpenStack Cloud Magnum Orchestration 7 (src):    openssh-7.2p2-74.35.1
Comment 12 Swamp Workflow Management 2019-01-28 14:09:42 UTC
openSUSE-SU-2019:0091-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
openSUSE Leap 15.0 (src):    openssh-7.6p1-lp150.8.9.1, openssh-askpass-gnome-7.6p1-lp150.8.9.1
Comment 13 Swamp Workflow Management 2019-01-29 14:14:04 UTC
openSUSE-SU-2019:0093-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
openSUSE Leap 42.3 (src):    openssh-7.2p2-29.1, openssh-askpass-gnome-7.2p2-29.1
Comment 20 Swamp Workflow Management 2019-02-19 09:00:13 UTC
This is an autogenerated message for OBS integration:
This bug (1121821) was mentioned in
https://build.opensuse.org/request/show/677282 Factory / openssh
Comment 23 Swamp Workflow Management 2019-02-26 20:13:58 UTC
SUSE-SU-2019:0496-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1121816,1121821,1125687
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Module for Server Applications 15 (src):    openssh-7.6p1-9.23.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    openssh-7.6p1-9.23.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    openssh-askpass-gnome-7.6p1-9.23.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    openssh-7.6p1-9.23.1
Comment 24 Swamp Workflow Management 2019-03-08 14:12:07 UTC
openSUSE-SU-2019:0307-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 1121816,1121821,1125687
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
openSUSE Leap 15.0 (src):    openssh-7.6p1-lp150.8.15.2, openssh-askpass-gnome-7.6p1-lp150.8.15.1
Comment 28 Swamp Workflow Management 2019-04-01 16:25:20 UTC
An update workflow for this issue was started.
This issue was rated as important.
Please submit fixed packages until 2019-04-08.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64248
Comment 30 Swamp Workflow Management 2019-04-11 19:10:19 UTC
SUSE-SU-2019:14016-1: An update that solves two vulnerabilities and has four fixes is now available.

Category: security (moderate)
Bug References: 1090671,1115550,1119183,1121816,1121821,1131709
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    openssh-6.6p1-41.18.1, openssh-askpass-gnome-6.6p1-41.18.1
SUSE Linux Enterprise Debuginfo 11-SP3 (src):    openssh-6.6p1-41.18.1, openssh-askpass-gnome-6.6p1-41.18.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 31 Swamp Workflow Management 2019-04-12 19:11:14 UTC
SUSE-SU-2019:0941-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (moderate)
Bug References: 1090671,1115550,1119183,1121816,1121821
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    openssh-6.6p1-54.32.1, openssh-askpass-gnome-6.6p1-54.32.1
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    openssh-6.6p1-54.32.1, openssh-askpass-gnome-6.6p1-54.32.1
SUSE Linux Enterprise Server 12-LTSS (src):    openssh-6.6p1-54.32.1, openssh-askpass-gnome-6.6p1-54.32.1

*** NOTE: This information is not intended to be used for external
    communication, because this may only be a partial fix.
    If you have questions please reach out to maintenance coordination.
Comment 32 Swamp Workflow Management 2019-04-25 13:11:53 UTC
SUSE-SU-2019:14030-1: An update that solves two vulnerabilities and has four fixes is now available.

Category: security (moderate)
Bug References: 1090671,1115550,1119183,1121816,1121821,1131709
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    openssh-6.6p1-36.20.1, openssh-askpass-gnome-6.6p1-36.20.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    openssh-6.6p1-36.20.1, openssh-askpass-gnome-6.6p1-36.20.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 33 Swamp Workflow Management 2019-04-29 10:19:58 UTC
SUSE-SU-2019:0125-2: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 34 Swamp Workflow Management 2019-06-17 19:12:11 UTC
SUSE-SU-2019:1524-1: An update that solves two vulnerabilities and has four fixes is now available.

Category: security (moderate)
Bug References: 1065237,1090671,1119183,1121816,1121821,1131709
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
SUSE OpenStack Cloud 7 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Server 12-SP4 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Server 12-SP3 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Server 12-SP2-BCL (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Desktop 12-SP4 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Linux Enterprise Desktop 12-SP3 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE Enterprise Storage 4 (src):    openssh-7.2p2-74.42.8, openssh-askpass-gnome-7.2p2-74.42.10
SUSE CaaS Platform ALL (src):    openssh-7.2p2-74.42.8
SUSE CaaS Platform 3.0 (src):    openssh-7.2p2-74.42.8
OpenStack Cloud Magnum Orchestration 7 (src):    openssh-7.2p2-74.42.8

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 35 Swamp Workflow Management 2019-06-24 13:31:37 UTC
openSUSE-SU-2019:1602-1: An update that solves two vulnerabilities and has four fixes is now available.

Category: security (moderate)
Bug References: 1065237,1090671,1119183,1121816,1121821,1131709
CVE References: CVE-2019-6109,CVE-2019-6111
Sources used:
openSUSE Leap 42.3 (src):    openssh-7.2p2-35.1, openssh-askpass-gnome-7.2p2-35.1
Comment 36 Alexandros Toptsoglou 2020-04-24 15:56:44 UTC
Done