VYPR
Medium severity5.3NVD Advisory· Published Oct 26, 2017· Updated May 13, 2026

CVE-2017-15906

CVE-2017-15906

Description

The process_open function in sftp-server.c in OpenSSH before 7.6 does not properly prevent write operations in readonly mode, which allows attackers to create zero-length files.

Affected products

26

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.