CVE-2016-5725
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 24.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allows remote SFTP servers to write to arbitrary files via a ..\ (dot dot backslash) in a response to a recursive GET command.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 24.14% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- jcraft/jsch
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/138809/jsch-0.1.53-Path-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Sep/53Mailing List, Third Party Advisory
- http://www.jcraft.com/jsch/ChangeLogRelease Notes
- http://www.securityfocus.com/bid/93100Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3115
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-5725Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/04/msg00017.html
- https://www.exploit-db.com/exploits/40411/Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
- http://packetstormsecurity.com/files/138809/jsch-0.1.53-Path-Traversal.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2016/Sep/53Mailing List, Third Party Advisory
- http://www.jcraft.com/jsch/ChangeLogRelease Notes
- http://www.securityfocus.com/bid/93100Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3115
- https://github.com/tintinweb/pub/tree/master/pocs/cve-2016-5725Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/04/msg00017.html
- https://www.exploit-db.com/exploits/40411/Third Party Advisory, VDB Entry
- https://www.oracle.com/security-alerts/cpuApr2021.html
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2020.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.