Bug 1121818 (CVE-2019-6110) - VUL-0: CVE-2019-6110: openssh-openssl1,openssh,putty: scp client spoofing via stderr
Summary: VUL-0: CVE-2019-6110: openssh-openssl1,openssh,putty: scp client spoofing via...
Status: RESOLVED FIXED
Alias: CVE-2019-6110
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Hans Petter Jansson
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/222747/
Whiteboard: CVSSv3:SUSE:CVE-2019-6110:4.6:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-14 10:37 UTC by Karol Babioch
Modified: 2024-07-03 08:03 UTC (History)
11 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---
gabriele.sonnu: needinfo? (hpj)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2019-01-14 10:37:42 UTC
4. CWE-451: scp client spoofing via stderr [CVE-2019-6110]

Due to accepting and displaying arbitrary stderr output from the scp server, a
malicious server can manipulate the client output, for example to employ ANSI codes
to hide additional files being transferred.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-6110
http://seclists.org/oss-sec/2019/q1/63
https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
https://sintonen.fi/advisories/scp-name-validator.patch
Comment 1 Andreas Stieger 2019-01-16 16:11:11 UTC
on openSUSE: also putty(pscp).
Comment 6 Swamp Workflow Management 2019-01-18 17:12:27 UTC
SUSE-SU-2019:0125-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server 12-SP1-LTSS (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1
SUSE Linux Enterprise Server 12-LTSS (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1
Comment 7 Swamp Workflow Management 2019-01-18 17:15:36 UTC
SUSE-SU-2019:0126-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Module for Server Applications 15 (src):    openssh-7.6p1-9.13.1
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (src):    openssh-7.6p1-9.13.1
SUSE Linux Enterprise Module for Desktop Applications 15 (src):    openssh-askpass-gnome-7.6p1-9.13.1
SUSE Linux Enterprise Module for Basesystem 15 (src):    openssh-7.6p1-9.13.1
Comment 8 Swamp Workflow Management 2019-01-18 20:10:14 UTC
SUSE-SU-2019:13931-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    openssh-6.6p1-36.12.1, openssh-askpass-gnome-6.6p1-36.12.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    openssh-6.6p1-36.12.1, openssh-askpass-gnome-6.6p1-36.12.1
Comment 9 Swamp Workflow Management 2019-01-21 14:13:02 UTC
SUSE-SU-2019:0132-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE OpenStack Cloud 7 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP3 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Desktop 12-SP4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Linux Enterprise Desktop 12-SP3 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE Enterprise Storage 4 (src):    openssh-7.2p2-74.35.1, openssh-askpass-gnome-7.2p2-74.35.1
SUSE CaaS Platform ALL (src):    openssh-7.2p2-74.35.1
SUSE CaaS Platform 3.0 (src):    openssh-7.2p2-74.35.1
OpenStack Cloud Magnum Orchestration 7 (src):    openssh-7.2p2-74.35.1
Comment 11 Swamp Workflow Management 2019-01-28 14:09:34 UTC
openSUSE-SU-2019:0091-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
openSUSE Leap 15.0 (src):    openssh-7.6p1-lp150.8.9.1, openssh-askpass-gnome-7.6p1-lp150.8.9.1
Comment 12 Swamp Workflow Management 2019-01-29 14:13:55 UTC
openSUSE-SU-2019:0093-1: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
openSUSE Leap 42.3 (src):    openssh-7.2p2-29.1, openssh-askpass-gnome-7.2p2-29.1
Comment 14 Vítězslav Čížek 2019-02-05 16:44:57 UTC
We reverted the fixes for the recent scp issues (CVE-2019-6109, CVE-2019-6110, CVE-2019-6111) due to the reported regression (bug 1123028) causing a change of scp's behavior.

None of the patches came from upstream and there could be more incompatibilities lurking.

Upstream assessment (https://lists.gt.net/openssh/dev/73013#73013) of CVE-2019-6110:

"We don't consider the report relating to stderr to be a vulnerability -
lots of stuff depends on stderr being present (e.g. login warning
banners that some people inexplicably love) and it's impractical for
scp to selectively process them. The machine you just logged into can
print junk to your screen, so what?"
Comment 16 Swamp Workflow Management 2019-04-29 10:19:47 UTC
SUSE-SU-2019:0125-2: An update that fixes four vulnerabilities is now available.

Category: security (important)
Bug References: 1121571,1121816,1121818,1121821
CVE References: CVE-2018-20685,CVE-2019-6109,CVE-2019-6110,CVE-2019-6111
Sources used:
SUSE Linux Enterprise Server for SAP 12-SP1 (src):    openssh-6.6p1-54.26.1, openssh-askpass-gnome-6.6p1-54.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 17 Robert Frohl 2021-12-06 08:23:41 UTC
missing for SUSE:SLE-11-SP3:Update/openssh-openssl1