WinSCP Multiple Vulnerabilities
Last Update Date:
28 Aug 2014
Release Date:
25 Aug 2014
3920
Views
RISK: Medium Risk
TYPE: Clients - Productivity Products
Multiple vulnerabilities have been identified in WinSCP, which can be exploited by malicious people to disclose potentially sensitive information, bypass certain security restrictions, cause a DoS (Denial of Service), and compromise a user's system.
Impact
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
System / Technologies affected
- WinSCP 5.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 5.5.5.
Vulnerability Identifier
- CVE-2014-3505
- CVE-2014-3506
- CVE-2014-3507
- CVE-2014-3508
- CVE-2014-3509
- CVE-2014-3510
- CVE-2014-3511
- CVE-2014-3512
- CVE-2014-5139
Source
Related Link
Share with