Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2020-15778
HistoryJul 24, 2020 - 2:15 p.m.

CVE-2020-15778

2020-07-2414:15:00
Alpine Linux Development Team
security.alpinelinux.org
270

0.004 Low

EPSS

Percentile

74.3%

DISPUTED scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of “anomalous argument transfers” because that could “stand a great chance of breaking existing workflows.”

OSVersionArchitecturePackageVersionFilename
Alpine3.10-mainnoarchopenssh= 8.1_p1-r0UNKNOWN
Alpine3.11-mainnoarchopenssh= 8.1_p1-r1UNKNOWN