Total vulnerabilities in the database
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
Software | From | Fixed in |
---|---|---|
openbsd / openssh | - | 7.9.x |
winscp / winscp | - | 5.13.x |
siemens / scalance_x204rna_firmware | - | 3.2.7 |
siemens / scalance_x204rna_eec_firmware | - | 3.2.7 |