CVE-2018-20684
10.01.2019, 21:29
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.Enginsight
Vendor | Product | Version |
---|---|---|
winscp | winscp | 𝑥 ≤ 5.13.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References