QSearchQSearch

CVE-2019-6109

6.8 MEDIUM

An issue was discovered in OpenSSH 7.9

Published: 2019-01-31 · Last updated: 2026-05-28

Severity and scoring

CVSS
6.8 MEDIUM
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE
CWE-116

Affected products

VendorProduct
canonicaldebian_linux, element_software, enterprise_linux
debiandebian_linux, element_software, enterprise_linux
fedoraprojectdebian_linux, element_software, enterprise_linux
fujitsudebian_linux, element_software, enterprise_linux
netappdebian_linux, element_software, enterprise_linux
openbsddebian_linux, element_software, enterprise_linux
redhatdebian_linux, element_software, enterprise_linux
siemensdebian_linux, element_software, enterprise_linux
winscpdebian_linux, element_software, enterprise_linux

Description

An issue was discovered in OpenSSH 7.9. Due to missing character encoding in the progress display, a malicious server (or Man-in-The-Middle attacker) can employ crafted object names to manipulate the client output, e.g., by using ANSI control codes to hide additional files being transferred. This affects refresh_progress_meter() in progressmeter.c.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2026-1767 A flaw was found in the GNOME localsearch (previously known as tracker-miners) MP3 Extractor `tracker-extract-mp3` component (5.6 MEDIUM)
  • CVE-2026-1766 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracker-extract-mp3 com... (5.6 MEDIUM)
  • CVE-2026-11793 A stack buffer overflow flaw was found in 389 Directory Server (4.9 MEDIUM)
  • CVE-2026-11790 A flaw was found in 389 Directory Server (4.9 MEDIUM)
  • CVE-2026-11789 A flaw was found in 389 Directory Server (4.9 MEDIUM)

Same CWE

  • CVE-2026-45011 ApostropheCMS is an open-source Node.js content management system (7.3 HIGH)
  • CVE-2026-54133 jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP app... (9.8 CRITICAL)
  • CVE-2026-48485 Quest Bot is an opensource Discord Bot
  • CVE-2026-47188 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support
  • CVE-2026-47175 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support