CVE-2019-14889
HIGHlibssh < 0.9.3 and < 0.8.8 - OS Command Injection via SCP Path Parameter
Title source: llmDescription
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
References (11)
Core 11
Core References
Third Party Advisory vendor-advisory
https://usn.ubuntu.com/4219-1/
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.html
Mailing List, Third Party Advisory mailing-list
https://lists.debian.org/debian-lts-announce/2019/12/msg00020.html
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7JJWJTXVWLLJTVHBPGWL7472S5FWXYQR/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EV2ONSPDJCTDVORCB4UGRQUZQQ46JHRN/
Mailing List, Third Party Advisory vendor-advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.html
Third Party Advisory vendor-advisory
https://security.gentoo.org/glsa/202003-27
Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14889
Vendor Advisory
https://www.libssh.org/security/advisories/CVE-2019-14889.txt
Third Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/05/msg00029.html
Scores
CVSS v3
8.8
EPSS
0.0112
EPSS Percentile
78.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (10)
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
18.04
canonical/ubuntu_linux
19.04
canonical/ubuntu_linux
19.10
debian/debian_linux
8.0
fedoraproject/fedora
30
fedoraproject/fedora
31
libssh/libssh
< 0.8.8
opensuse/leap
15.1
oracle/mysql_workbench
< 8.0.19
Published
Dec 10, 2019
Tracked Since
Feb 18, 2026