Loading
In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.
Cite this page
CVE-2019-6110. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2019-6110
Use CWE-838, Openbsd vendor hub and Openssh product page to widen CVE-2019-6110 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-6387, CVE-2026-35385 and CVE-2023-51767 for nearby disclosures in the same product family.