CVE-2018-20684

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/01/2019
Last modified:
15/01/2020

Description

In WinSCP before 5.14 beta, due to missing validation, the scp implementation would accept arbitrary files sent by the server, potentially overwriting unrelated files. This affects TSCPFileSystem::SCPSink in core/ScpFileSystem.cpp.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:* 5.13.7 (including)