CVE-2019-14889: Canonical Ubuntu Linux
High severity, CVSS 8.8. EPSS: 3.2% chance of exploitation in the next 30 days.
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become possible for an attacker to inject arbitrary commands, leading to a compromise of the remote target.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
- Debian Debian Linux: version 8.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Libssh Libssh: before 0.8.8 (fixed in 0.8.8); from 0.9.0, before 0.9.3 (fixed in 0.9.3)
- Opensuse Leap: version 15.1 only
- Oracle MySQL Workbench: up to and including 8.0.19
Published 2019-12-10. Last modified 2026-06-17.