{"id":"ECHO-701c-0998-5cef","summary":"This vulnerability is disputed by the openssh maintainers, and is considered\nexpected behavior. As long as scp is used within trusted servers, this\nvulnerability should not affect the image.\nhttps://security-tracker.debian.org/tracker/CVE-2019-6110\nhttps://lists.mindrot.org/pipermail/openssh-unix-dev/2019-January/037475.html\n","modified":"2026-09-15T03:42:38.124400155Z","published":"2026-01-29T00:50:46.461903Z","withdrawn":"2025-08-03T16:59:07.240Z","upstream":["CVE-2019-6110","GHSA-mv2j-4mm8-9xgv"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2019-6110"}],"affected":[{"package":{"name":"openssh","ecosystem":"Echo","purl":"pkg:deb/echo/openssh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1:9.2p1-2+deb12u6"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-701c-0998-5cef.json"}}],"schema_version":"1.9.0"}