Software-update: WinSCP 6.5.7
Versie 6.5.7 van WinSCP is verschenen. Met dit open source programma kunnen op een veilige manier bestanden tussen twee computers worden gekopieerd. Het programma ondersteunt FTP, SFTP en SCP. WinSCP is niet alleen als een opzichzelfstaand programma beschikbaar, maar ook als plug-in voor de programma's FAR Manager en Altap Salamander. Hieronder is de changelog voor deze uitgave te vinden.
Changes in version 6.5.7:Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian.TLS/SSL core upgraded to OpenSSL 3.3.7.SSH private key tools (PuTTYgen and Pageant) upgraded to PuTTY 0.85. SSH core upgraded to include some fixes.It brings the following change:Security issue: fixed a remotely triggerable use-after-free in Pageant. pageant-deferred-decryption-uafSecurity issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. etm-large-packet-overflowSecurity issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. argon2-parameter-checksDenial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. maxpkt-0-tight-loopSecurity issue: fixed a remotely triggerable double-free in RSA key exchange. rsakex-double-freeMinor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. ecdsa-remotely-triggerable-assertionBack-propagated fixes from 6.6.2 beta release:Bug fix: Failure setting Session.DebugLogPath when running in impersonated context. 2441Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6.
Translations completed: Croatian, Finnish, Georgian, Italian and Serbian, and updated: Slovenian.TLS/SSL core upgraded to OpenSSL 3.3.7.SSH private key tools (PuTTYgen and Pageant) upgraded to PuTTY 0.85. SSH core upgraded to include some fixes.It brings the following change:Security issue: fixed a remotely triggerable use-after-free in Pageant. pageant-deferred-decryption-uafSecurity issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. etm-large-packet-overflowSecurity issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. argon2-parameter-checksDenial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. maxpkt-0-tight-loopSecurity issue: fixed a remotely triggerable double-free in RSA key exchange. rsakex-double-freeMinor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. ecdsa-remotely-triggerable-assertionSecurity issue: fixed a remotely triggerable use-after-free in Pageant. pageant-deferred-decryption-uafSecurity issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. etm-large-packet-overflowSecurity issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. argon2-parameter-checksDenial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. maxpkt-0-tight-loopSecurity issue: fixed a remotely triggerable double-free in RSA key exchange. rsakex-double-freeMinor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. ecdsa-remotely-triggerable-assertion
Security issue: fixed a remotely triggerable use-after-free in Pageant. pageant-deferred-decryption-uafSecurity issue: fixed a remotely triggerable buffer overflow if the OpenSSH encrypt-then-MAC cipher modes are in use. etm-large-packet-overflowSecurity issue: fixed a buffer overflow in private key decryption, if the private key is constructed maliciously. argon2-parameter-checksDenial-of-service security fixes: a server can trigger a tight loop in WinSCP, and even a MITM can make it consume unlimited memory at startup. maxpkt-0-tight-loopSecurity issue: fixed a remotely triggerable double-free in RSA key exchange. rsakex-double-freeMinor security issue: fixed a remotely triggerable crash in NIST ECDSA signature verification. ecdsa-remotely-triggerable-assertionBack-propagated fixes from 6.6.2 beta release:Bug fix: Failure setting Session.DebugLogPath when running in impersonated context. 2441Bug fix: Failure setting Session.DebugLogPath when running in impersonated context. 2441
Bug fix: Failure setting Session.DebugLogPath when running in impersonated context. 2441Bug fix: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. CVE-2026-45447 fix from OpenSSL 3.4.6.
Source:
Tweakers.net