CVE-2018-20684

winscp/winscp
on github

Published

Severity

CVSS v3:
7.5 HIGH
CVSS v2:
6.4 MEDIUM

Description

In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*n/a5.13.7 (including)*

External Links