Debian Netkit-Rsh vulnerabilities
2 known vulnerabilities affecting debian/netkit-rsh.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2019-7283P3MEDIUMCVSS 5.9fixed in netkit-rsh 0.17-20 (bookworm)2019
CVE-2019-7283 [MEDIUM] CVE-2019-7283: netkit-rsh - An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the...
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is
debian
CVE-2019-7282P4MEDIUMCVSS 5.3fixed in netkit-rsh 0.17-20 (bookworm)2019
CVE-2019-7282 [MEDIUM] CVE-2019-7282: netkit-rsh - In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to byp...
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
Scope: local
bookworm: resolved (fixed in 0.17-20)
bullseye: resolved (fixed in 0.17-20)
debian