Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2019-14889 Details

Description

A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://lists.opensuse.org/opensuse-security-announce/2019-12/msg00033.html CVEMailing ListThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00047.html CVEMailing ListThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14889 CVEIssue TrackingPatchThird Party Advisory
https://lists.debian.org/debian-lts-announce/2019/12/msg00020.html CVEMailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/05/msg00029.html CVE

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')[email protected]
CWE-78Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')[email protected]

Affected Products

ProductVersions

Change History

16 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2019-14889
NVD Published Date:
Dec 10, 2019
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2019-14889 Details - Not Deferred