libssh Vulnerability

Please post here if you have problems in using Wing FTP Server.
Post Reply
fn-sysop
Posts: 2
Joined: Fri Oct 19, 2018 1:47 pm

libssh Vulnerability

Post by fn-sysop »

Hello,

A flaw in libssh was published a few days ago, https://threatpost.com/libssh-authentic ... rs/138399/" rel="nofollow

From your release notes I can see that in Wing FTP Server v4.8.7, Released: 19/Apr/2017, you updated to libssh 0.7.5. Is there a timeframe for updating to 0.7.6 to mitigate this serious vulnerability?

Thanks,
jadams5
Posts: 2
Joined: Fri Oct 19, 2018 3:21 pm

Re: libssh Vulnerability

Post by jadams5 »

This needs patched ASAP, Wing FTP instances are sitting ducks until this is resolved unless they're somehow not vulnerable.
FTP
Site Admin
Posts: 2078
Joined: Tue Sep 29, 2009 6:09 am

Re: libssh Vulnerability

Post by FTP »

OK, SFTP authentication part is handled by WingFTP, not libssh. So I think WingFTP won't be effected by this vulnerability.
jadams5
Posts: 2
Joined: Fri Oct 19, 2018 3:21 pm

Re: libssh Vulnerability

Post by jadams5 »

Is a new release still planned or are you confident the current version isn't vulnerable? Thanks!
FTP
Site Admin
Posts: 2078
Joined: Tue Sep 29, 2009 6:09 am

Re: libssh Vulnerability

Post by FTP »

Yes, in WingFTP, SFTP authentication is not handled libssh. Anyway, we will update libssh in the next release, not for this vulnerability.
fn-sysop
Posts: 2
Joined: Fri Oct 19, 2018 1:47 pm

Re: libssh Vulnerability

Post by fn-sysop »

Thanks for the clarification
FTP
Site Admin
Posts: 2078
Joined: Tue Sep 29, 2009 6:09 am

Re: libssh Vulnerability

Post by FTP »

The new version 6.0.1 has been released, and libssh is updated to v0.7.7 now.
Post Reply