Remote Command Injection in libssh Versions Prior to 0.9.3 and 0.8.8
CVE-2019-14889
7.1HIGH
What is CVE-2019-14889?
A security flaw exists in the libssh API function ssh_scp_new(), which is found in versions before 0.9.3 and 0.8.8. When the libssh SCP client connects to a server, the scp command executed on the server can include a user-defined path. If implemented in a manner that allows user influence over the function's third parameter, an attacker may gain the ability to inject arbitrary commands. This vulnerability poses a risk of compromising the remote target, resulting in unauthorized access and potential data breaches.
Affected Version(s)
libssh All libssh versions before 0.9.3
libssh All libssh versions before 0.8.8