REDHAT-BUG-1860487: Command Injection
scp in OpenSSH through 8.3p1 allows command injection in scp.c remote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."
Reference: https://www.openssh.com/security.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1860487?
REDHAT-BUG-1860487 has been classified as a high severity vulnerability due to its potential for command injection.
How do I fix REDHAT-BUG-1860487?
To mitigate REDHAT-BUG-1860487, upgrade OpenSSH to a version higher than 8.3p1 that addresses this vulnerability.
What software is affected by REDHAT-BUG-1860487?
REDHAT-BUG-1860487 affects OpenSSH versions starting from 8.3p1.
What is the nature of the vulnerability in REDHAT-BUG-1860487?
The vulnerability in REDHAT-BUG-1860487 is due to command injection allowing backtick characters in the destination argument of the scp command.
Is there a workaround for REDHAT-BUG-1860487?
A temporary workaround for REDHAT-BUG-1860487 includes avoiding the use of the scp command until the software is updated.