MGASA-2016-0118
Dashboard / Vulnerabilities / MGASA-2016-0118
Summary: Updated filezilla packages fix security vulnerability
Details: Many versions of PSCP in PuTTY prior to 0.67 have a stack corruption vulnerability in their treatment of the 'sink' direction (i.e. downloading from server to client) of the old-style SCP protocol. In order for this vulnerability to be exploited, the user must connect to a malicious server and attempt to download any file (CVE-2016-2563). FileZilla was vulnerable to this issue as it bundles a copy of PuTTY. The filezilla package has been updated to version 3.16.1, which fixes this issue and has many other fixes and enhancements.
References: https://advisories.mageia.org/MGASA-2016-0118.html, https://bugs.mageia.org/show_bug.cgi?id=17943, http://www.chiark.greenend.org.uk/~sgtatham/putty/wishlist/vuln-pscp-sink-sscanf.html, http://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html, https://filezilla-project.org/
Affected packages
Package
Name: filezilla
Purl: pkg:rpm/mageia/filezilla?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
