New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Possible security issue with WinSCP < 5.14 #279
Comments
Fixed in original WinSCP source here: https://winscp.net/tracker/1675 Pull request #280 |
0xABD Can't build than try apply Your patch to Git dbb8ff2 possible is my typo, but if use VC2010/2015 DLL not build .:( |
I built it including those fixes without any problem. I used VS2017 though. |
Ok. Only this compiller not't tested - no time... |
Build Ok!, problem's source is my typo. Fixed, but not tested. Build in to VC2010. P.S. Как обычно - одновременно делать работу, и писать бумаги - какой злой дух придумал сиё наказание!?:( Да мне легче дивизию чертей наловить, обстричь, рога поотшибать и вместе с шерстью сдать в счёт госпаставок - в Аду тепло, не замёрзнут.:) |
Tested - Ok! Additional test - download FreeBSD 12 STABLE images - it's not so easy to get to them. on the servers of the daemon, a cascade of inter-server symlinks is used - the images lie on a cluster of NFS servers and this is a good test for "have we not broken the work with symlinks and FTP?" and work with complex server systems. The same cascade, for example, does not allow to see the real size of the file ftp://ftp.freebsd.org/pub/FreeBSD/ports/ports/ports.tar.gz - through the symlink it is addressed ftp://ftp.freebsd.org/pub/ FreeBSD/development/tarballs/ports_current.tar.gz and if you don’t know this, you won’t find the file. |
Whats new?:) If try VC++2010 build and open for update 7-Zip archive in to local FTP have crash in to GetFilesW(): and stack:
(this build not have .PDB removed my toolkit then assembly). I try VC++2015 build and skipik VC++2017 build - possible also my typo? "Minidump" have "small" file size -- only 476 mb (this computer have is 16 Gb physical RAM). |
I find source for problem's - typo in to NetBoxRus.lng::212 - just diff:
|
VC++2010 NetBox v2.4.5.531 Git-a7345ca4f minimal OS required: x86 - WinXP SP3, AMD64 - Vista . Fix a typo in a failed commit |
@michaellukashov How can I help further with this issue? Also, how do we include the fix to Far mainline? |
Reported into Far bug tracker at https://bugs.farmanager.com/view.php?id=3705 |
merged |
https://www.zdnet.com/article/scp-implementations-impacted-by-36-years-old-security-flaws/
The text was updated successfully, but these errors were encountered: