VulnerabilityModified
CVE-2019-7282
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename.
MEDIUM 5.9EPSS 2.07%
Does this matter?
Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.
Description
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 2.07% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- netkit/netkit · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- https://bugs.debian.org/920486Exploit, Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DU33YVEDGFDMAZPSRQTRVKSKG4FAX7QB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSEX3TKX2DBUKG4A7VJFDLSMZIBJQZ3G/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA24VQJATZWYV42JG2PQUW7IHIZS7UKP/
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtNot Applicable
- https://bugs.debian.org/920486Exploit, Issue Tracking, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00016.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DU33YVEDGFDMAZPSRQTRVKSKG4FAX7QB/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSEX3TKX2DBUKG4A7VJFDLSMZIBJQZ3G/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NA24VQJATZWYV42JG2PQUW7IHIZS7UKP/
- https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txtNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.