CVE-2018-20684
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
10/01/2019
Last modified:
15/01/2020
Description
In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
6.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:* | 5.13.7 (including) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/106526
- https://github.com/winscp/winscp/commit/49d876f2c5fc00bcedaa986a7cf6dedd6bf16f54
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
- https://winscp.net/eng/docs/history
- https://winscp.net/tracker/1675
- https://www.oracle.com/security-alerts/cpujan2020.html



