vendor:
OpenSSH
by:
Vladimir Kotal
7.5
CVSS
HIGH
Remote File Overwrite Vulnerability
20
CWE
Product Name: OpenSSH
Affected Version From: 1.2.x
Affected Version To: 1.2.x
Patch Exists: YES
Related CWE: CVE-2002-0083
CPE: //a:openssh:openssh:1.2.x
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Mac, Windows
2002
SCP 1.2.x Remote File Overwrite Vulnerability
A vulnerability exists in the 1.2.x releases of scp which, if properly exploited using a modified scp binary on the server end, can permit the remote server to spoof local pathnames and overwrite files belonging to the local user. As a proof of concept, I created trivial scp replacement (put it on remote machine in the place of original scp binary - usually in /usr/local/bin). It will try to exploit any file transfer, creating setuid /tmp/ScpIsBuggy file on client system.
Mitigation:
It is recommended to upgrade to the latest version of scp and use it with caution.