4.3
CVSSv2

CVE-2019-7282

Published: 31/01/2019 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In NetKit up to and including 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netkit netkit

debian debian linux 9.0

fedoraproject fedora 34

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #920486 netkit-rsh: CVE-2019-7282 CVE-2019-7283 Package: rsh-client; Maintainer for rsh-client is Alberto Gonzalez Iniesta <agi@inittaborg>; Source for rsh-client is src:netkit-rsh (PTS, buildd, popcon) Reported by: Hiroyuki YAMAMORI <h-yamamo@db3so-netnejp> Date: Sat, 26 Jan 2019 05:24:0 ...