CVE-2018-20685: Canonical Ubuntu Linux

Medium severity, CVSS 5.3. EPSS: 3.7% chance of exploitation in the next 30 days.

In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 18.10 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • Fujitsu m10-1 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Fujitsu m10-4 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Fujitsu m10-4s Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-1 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-2 Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Fujitsu m12-2s Firmware: before xcp2361 (fixed in xcp2361); before xcp3070 (fixed in xcp3070)
  • Netapp Cloud Backup: affected versions not specified
  • Netapp Element Software: affected versions not specified
  • Netapp Ontap Select Deploy: affected versions not specified
  • Netapp Steelstore Cloud Integrated Storage: affected versions not specified
  • Netapp Storage Automation Store: affected versions not specified
  • OpenBSD OpenSSH: up to and including 7.9
  • Oracle Solaris: version 10 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Red Hat Enterprise Linux Eus: version 8.1 only; version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Aus: version 8.2 only; version 8.4 only; version 8.6 only
  • Red Hat Enterprise Linux Server Tus: version 8.2 only; version 8.4 only; version 8.6 only
  • Siemens Scalance x204rna Eec Firmware: before 3.2.7 (fixed in 3.2.7)
  • Siemens Scalance x204rna Firmware: before 3.2.7 (fixed in 3.2.7)
  • Winscp Winscp: up to and including 5.13

Published 2019-01-10. Last modified 2026-06-17.