SCP Server Verification Issues

Discussion in 'News Aggregator' started by Packet Storm, 16 Jan 2019.

  1. Packet Storm

    Packet Storm Guest

    Many scp clients fail to verify if the objects returned by the scp server match those it asked for. This issue dates back to 1983 and rcp, on which scp is based. A separate flaw in the client allows the target directory attributes to be changed arbitrarily. Finally, two vulnerabilities in clients may allow server to spoof the client output.

    Continue reading...
     

Share This Page

Loading...