Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary files via a .. (dot dot) attack.
https://exchange.xforce.ibmcloud.com/vulnerabilities/5312
http://frontal2.mandriva.com/security/advisories?name=MDKSA-2000:057