CVE-2004-0175: Path Traversal
Published Jun 3, 2004
·Updated
Directory traversal vulnerability in scp for OpenSSH before 3.4p1 allows remote malicious servers to overwrite arbitrary files. NOTE: this may be a rediscovery of CVE-2000-0992.
Affected Software
15 affected components
OpenBSD OpenSSH=3.1
OpenBSD OpenSSH=3.0.2p1
OpenBSD OpenSSH=3.2.3p1
OpenBSD OpenSSH=3.1p1
OpenBSD OpenSSH=3.0
OpenBSD OpenSSH=3.2
OpenBSD OpenSSH=3.0.1p1
OpenBSD OpenSSH=3.3
OpenBSD OpenSSH=3.2.2p1
OpenBSD OpenSSH=3.0.2
OpenBSD OpenSSH=3.4p1
OpenBSD OpenSSH=3.0.1
OpenBSD OpenSSH=3.4
OpenBSD OpenSSH=3.0p1
OpenBSD OpenSSH=3.3p1
Remediation
Patch Available
Event History
Jun 3, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0175?
CVE-2004-0175 has a moderate severity rating due to the potential for overwriting arbitrary files.
2
How do I fix CVE-2004-0175?
To fix CVE-2004-0175, update OpenSSH to version 3.4p1 or later.
3
Which versions of OpenSSH are affected by CVE-2004-0175?
CVE-2004-0175 affects OpenSSH versions prior to 3.4p1, including 3.1, 3.2, and 3.3.
4
What type of vulnerability is CVE-2004-0175?
CVE-2004-0175 is a directory traversal vulnerability that allows file overwriting.
5
Can CVE-2004-0175 be exploited remotely?
Yes, CVE-2004-0175 can be exploited remotely by malicious servers.