Security Advisory

CVE-2017-15906

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-10-26 00:00:00
Last updated 2026-05-28 17:56:04
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.