Description
In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1728-1 | openssh security update |
Debian DSA |
DSA-4387-1 | openssh security update |
EUVD |
EUVD-2018-13232 | In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. |
Ubuntu USN |
USN-3885-1 | OpenSSH vulnerabilities |
References
History
Wed, 17 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Canonical
Subscribe
Ubuntu Linux
Subscribe
Debian
Subscribe
Debian Linux
Subscribe
Fujitsu
Subscribe
M10-1
Subscribe
M10-1 Firmware
Subscribe
M10-4
Subscribe
M10-4 Firmware
Subscribe
M10-4s
Subscribe
M10-4s Firmware
Subscribe
M12-1
Subscribe
M12-1 Firmware
Subscribe
M12-2
Subscribe
M12-2 Firmware
Subscribe
M12-2s
Subscribe
M12-2s Firmware
Subscribe
Netapp
Subscribe
Cloud Backup
Subscribe
Element Software
Subscribe
Ontap Select Deploy
Subscribe
Steelstore Cloud Integrated Storage
Subscribe
Storage Automation Store
Subscribe
Openbsd
Subscribe
Openssh
Subscribe
Oracle
Subscribe
Solaris
Subscribe
Redhat
Subscribe
Enterprise Linux
Subscribe
Enterprise Linux Eus
Subscribe
Enterprise Linux Server Aus
Subscribe
Enterprise Linux Server Tus
Subscribe
Siemens
Subscribe
Scalance X204rna
Subscribe
Scalance X204rna Eec
Subscribe
Scalance X204rna Eec Firmware
Subscribe
Scalance X204rna Firmware
Subscribe
Winscp
Subscribe
Winscp
Subscribe
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-12-17T21:53:56.287Z
Reserved: 2019-01-10T00:00:00.000Z
Link: CVE-2018-20685
Updated: 2024-08-05T12:05:17.712Z
Status : Modified
Published: 2019-01-10T21:29:00.377
Modified: 2025-12-17T22:15:55.163
Link: CVE-2018-20685
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN