How to analyze the OpenSSH command injection vulnerability CVE-2020-15778
How to analyze the OpenSSH command injection vulnerability CVE-2020-15778. In view of this problem, this article introduces the corresponding analysis and solution in detail, hoping to help more partners who want to solve this problem to find a more simple and feasible method.
Introduction of loopholes
SCP (secure copy) is a command for secure remote file copying based on ssh login on linux systems, which can copy files and directories between linux.
A command injection vulnerability exists in the less than 8.3p1 version of the SCP command in OpenSSH. When a file is copied to a remote server, the file path is appended to the end of the local scp command, which can trigger a command injection vulnerability.
An attacker can use a backquote (`) file as a command injection to execute a scp command, which will be sent to a remote server and executed.
Affect the version
Version: