CVE-2019-7282
published 2019-01-31CVE-2019-7282: In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
2.07%
79.5th percentile
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | netkit-rsh | < netkit-rsh 0.17-20 (bookworm) | netkit-rsh 0.17-20 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| mit | krb5-appl | <= 1.0.3 | — |
| netkit | netkit | <= 0.17 | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
rsh vulnerability
vendor_ubuntu·2022-03-15
CVE-2019-7282 rsh vulnerability
Title: rsh vulnerability
Summary: rsh would allow unintended modification of target directory permissions.
Hiroyuki Yamamori discovered that rsh incorrectly handled certain
filenames. If a user or automated system were tricked into connecting to a
malicious rsh server, a remote attacker could possibly use this issue to
modify directory permissions.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
netkit-rsh: rcp access restriction bypass
vendor_redhat·2021-11-19·CVSS 5.3
CVE-2019-7282 [MEDIUM] CWE-281 netkit-rsh: rcp access restriction bypass
netkit-rsh: rcp access restriction bypass
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
A vulnerability was found in rsh. The vulnerability occurs due to bypass restrictions via the filename of [.] or an empty filename. This flaw allows an attacker to modify the permissions of the target directory on the client-side.
Statement: Red Hat Enterprise Linux 6 and 7 were affected but Out of Support Scope.
https://access.redhat.com/support/policy/updates/errata/
Package: rsh (Red Hat Enterprise Linux 6) - Out of support scope
Package: rsh (Red Hat Enterprise Linux 7
Red Hat
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
vendor_redhat·2021-02-02·CVSS 5.3
CVE-2019-25018 [MEDIUM] CWE-863 krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
krb5-appl: Improper directory name validation allows malicious server to bypass access restrictions
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
Package: krb5-appl (Red Hat Enterprise Linux 6) - Out of support scope
Debian
CVE-2019-7282: netkit-rsh - In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to byp...
vendor_debian·2019·CVSS 5.3
CVE-2019-7282 [MEDIUM] CVE-2019-7282: netkit-rsh - In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to byp...
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
Scope: local
bookworm: resolved (fixed in 0.17-20)
bullseye: resolved (fixed in 0.17-20)
GHSA
GHSA-xxwg-wfjg-vgjp: In the rcp client in MIT krb5-appl through 1
ghsa_unreviewed·2022-05-24·CVSS 5.3
CVE-2019-25018 [MEDIUM] CWE-863 GHSA-xxwg-wfjg-vgjp: In the rcp client in MIT krb5-appl through 1
In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.
GHSA
GHSA-xrxr-vcvh-gm7h: In NetKit through 0
ghsa_unreviewed·2022-04-30·CVSS 5.3
CVE-2019-7282 [MEDIUM] GHSA-xrxr-vcvh-gm7h: In NetKit through 0
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
OSV
CVE-2019-7282: In NetKit through 0
osv·2019-01-31·CVSS 5.3
CVE-2019-7282 [MEDIUM] CVE-2019-7282: In NetKit through 0
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.debian.org/920486https://lists.debian.org/debian-lts-announce/2021/11/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DU33YVEDGFDMAZPSRQTRVKSKG4FAX7QB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSEX3TKX2DBUKG4A7VJFDLSMZIBJQZ3G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA24VQJATZWYV42JG2PQUW7IHIZS7UKP/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txthttps://bugs.debian.org/920486https://lists.debian.org/debian-lts-announce/2021/11/msg00016.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DU33YVEDGFDMAZPSRQTRVKSKG4FAX7QB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSEX3TKX2DBUKG4A7VJFDLSMZIBJQZ3G/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA24VQJATZWYV42JG2PQUW7IHIZS7UKP/https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt
2019-01-31
Published