CVE-2017-15906
26.10.2017, 03:29
The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.Enginsight
Vendor | Product | Version |
---|---|---|
openbsd | openssh | 𝑥 < 7.6 |
oracle | sun_zfs_storage_appliance_kit | 8.8.6 |
debian | debian_linux | 8.0 |
netapp | active_iq_unified_manager | - |
netapp | cloud_backup | - |
netapp | clustered_data_ontap | - |
netapp | data_ontap_edge | - |
netapp | hci_management_node | - |
netapp | oncommand_unified_manager_core_package | - |
netapp | solidfire | - |
netapp | steelstore_cloud_integrated_storage | - |
netapp | storage_replication_adapter_for_clustered_data_ontap | 9.7 ≤ |
netapp | storage_replication_adapter_for_clustered_data_ontap | 9.6 |
netapp | vasa_provider_for_clustered_data_ontap | 6.0 ≤ 𝑥 ≤ 6.2 |
netapp | vasa_provider_for_clustered_data_ontap | 9.7 ≤ |
netapp | virtual_storage_console | 9.7 ≤ |
netapp | virtual_storage_console | 9.6 |
netapp | cn1610_firmware | - |
redhat | enterprise_linux_desktop | 7.0 |
redhat | enterprise_linux_eus | 7.6 |
redhat | enterprise_linux_eus | 7.7 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_aus | 7.7 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_server_tus | 7.7 |
redhat | enterprise_linux_workstation | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
openssh |
|
Common Weakness Enumeration
References