CVE-2018-20684

In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
Configurations

Configuration 1 (hide)

cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:01

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/106526 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/106526 - Third Party Advisory, VDB Entry
References () https://github.com/winscp/winscp/commit/49d876f2c5fc00bcedaa986a7cf6dedd6bf16f54 - Patch, Third Party Advisory () https://github.com/winscp/winscp/commit/49d876f2c5fc00bcedaa986a7cf6dedd6bf16f54 - Patch, Third Party Advisory
References () https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt - Mitigation, Third Party Advisory () https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt - Mitigation, Third Party Advisory
References () https://winscp.net/eng/docs/history - Release Notes, Vendor Advisory () https://winscp.net/eng/docs/history - Release Notes, Vendor Advisory
References () https://winscp.net/tracker/1675 - Patch, Vendor Advisory () https://winscp.net/tracker/1675 - Patch, Vendor Advisory
References () https://www.oracle.com/security-alerts/cpujan2020.html - () https://www.oracle.com/security-alerts/cpujan2020.html -

Information

Published : 2019-01-10 21:29

Updated : 2024-11-21 04:01


NVD link : CVE-2018-20684

Mitre link : CVE-2018-20684

CVE.ORG link : CVE-2018-20684


JSON object : View

Products Affected

winscp

  • winscp
CWE
CWE-20

Improper Input Validation