Security Advisory for SFTPPlus 3.39.0

A security advisory was created for SFTPPlus version 3.39.0 affecting the SCP protocol for which existing files were not always fully overwritten upon a new file upload request.

Customers using the SCP protocol are urged to upgrade to this version.

Any previous version contains a security issue when overwriting files over SCP. If the existing file that is overwritten is larger than the new file, the newly uploaded file is corrupted as it will continue to have the file size of the existing file and a mixed content with new file content and existing file content at the end.

This was a regression introduced in version 2.8.0.

An upgrade is recommended for any customer using the SCP protocol.

An upgrade is not required when only SFTP, FTPS or HTTPS are used.

You can check the full release notes here.