SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-7282

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename.

MEDIUM 5.9EPSS 2.07%

Does this matter?

Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.

Description

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
2.07% probability · 80th percentile
CISA KEV
Not listed
Affected
netkit/netkit · debian/debian linux · fedoraproject/fedora
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.