First published: Thu Jan 10 2019(Updated: )
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Winscp Winscp | <=5.13.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20684 is a vulnerability in WinSCP before 5.14 beta that allows arbitrary files sent by the server to potentially overwrite unrelated files.
The vulnerability in WinSCP allows arbitrary files sent by the server to potentially overwrite unrelated files.
CVE-2018-20684 has a severity rating of 7.5 (high).
To fix the CVE-2018-20684 vulnerability in WinSCP, you should update to version 5.14 beta or later.
You can find more information about CVE-2018-20684 at the following references: [1] http://www.securityfocus.com/bid/106526 [2] https://github.com/winscp/winscp/commit/49d876f2c5fc00bcedaa986a7cf6dedd6bf16f54 [3] https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt