In WinSCP before 5.14 beta, due to missing validation, the...
Vulnerability Description
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-20684
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/106526
- https://github.com/winscp/winscp/commit/49d876f2c5fc00bcedaa986a7cf6dedd6bf16f54
- https://winscp.net/eng/docs/history
- https://winscp.net/tracker/1675
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
- https://www.oracle.com/security-alerts/cpujan2020.html
More from winscp
View All →Affected Vendor
winscp
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.