7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
by @LeSuisse Activity log
- Created automatic suggestion
- @LeSuisse removed package opensshTest
- @LeSuisse removed package openssh-askpass
- @LeSuisse removed package perlPackages.NetOpenSSH
- @LeSuisse removed package perl5Packages.NetOpenSSH
- @LeSuisse removed package lxqt.lxqt-openssh-askpass
- @LeSuisse removed package perl538Packages.NetOpenSSH
- @LeSuisse removed package perl540Packages.NetOpenSSH
- @LeSuisse ignored reference https://m…
- @LeSuisse accepted
- @LeSuisse published on GitHub
In OpenSSH before 10.3, a file downloaded by scp may …
In OpenSSH before 10.3, a file downloaded by scp may be installed setuid or setgid, an outcome contrary to some users' expectations, if the download is performed as root with -O (legacy scp protocol) and without -p (preserve mode).
References
Affected products
- <10.3
Matching in nixpkgs
pkgs.openssh
Implementation of the SSH protocol
pkgs.openssh_hpn
Implementation of the SSH protocol with high performance networking patches
pkgs.openssh_gssapi
Implementation of the SSH protocol with GSSAPI support
pkgs.opensshWithKerberos
Implementation of the SSH protocol
Ignored packages (7)
pkgs.opensshTest
Implementation of the SSH protocol
pkgs.openssh-askpass
A passphrase dialog for OpenSSH and GTK
pkgs.perlPackages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.perl5Packages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.lxqt.lxqt-openssh-askpass
GUI to query passwords on behalf of SSH agents
pkgs.perl538Packages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
pkgs.perl540Packages.NetOpenSSH
Perl SSH client package implemented on top of OpenSSH
Package maintainers
-
@philiptaron Philip Taron <philip.taron@gmail.com>
-
@dasJ Janne Heß <janne@hess.ooo>
-
@Conni2461 Simon Hauser <simon-hauser@outlook.com>
-
@helsinki-Jo Joachim Ernst <joachim.ernst@helsinki-systems.de>
-
@wahjava Ashish SHUKLA <ashish.is@lostca.se>