Topic "Buffer overflow in WinSCP."

Author Message
vikas.adhangale
[View user's profile]

Joined: 2008-06-10
Posts: 1
Location: Pune
Hi all,

I'm a security professional, working in a reputed security firm. There is a possible overflow in WinSCP-3.8.0. WinSCP is not able to handle long filenames. This is true in case of long filenames of 255 characters long with normal alphanumeric characters and with specially crafted filenames as well. Once you try to copy files with long filenames, a buffer overrun occurs and windows terminates WinSCP instances. Very Happy

Best Regards,
Vikas Adhangale.
MOB: +91 9822052560
YIM: vikas_adhangale
Gtalk: vikas.adhangale
martin
[View user's profile]
Site Admin
Joined: 2002-12-10
Posts: 24530
Location: Prague, Czechia
Does the problem occur with the latest version? Also do you use SFTP or SCP? I'm not able to test it myself as I do not have a system available, where such a long filename can be created.
_________________
Martin Prikryl
Advertisements

You can post new topics in this forum






Search Site

What is WinSCP?

It is award-winning SFTP client, SCP client, FTPS client and FTP client integrated into one software program for file transfer to FTP server or secure SFTP server. [More]

And it's free!

Donate

About donations

$9   $19   $49   $99

About donations

Recommend

WinSCP Privacy Policy

WinSCP License