CVE-2017-15906

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

medium 5.3 CVSS 3.1
Published: Oct 26, 2017
Modified: May 28, 2026
Vendor: Openbsd
Product: Openssh
Versions: 8.8.6,8.0,9.6,7.0,7.6,7.7

Description

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

References

Related CVEs