CVE-2019-7282

MEDIUM

NetKit <0.17 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

References (6)

Core 6
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_misc
https://bugs.debian.org/920486
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/11/msg00016.html

Scores

CVSS v3 5.9
EPSS 0.0207
EPSS Percentile 79.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (5)
debian/debian_linux 9.0
fedoraproject/fedora 34
fedoraproject/fedora 35
fedoraproject/fedora 36
netkit/netkit < 0.17
Published Jan 31, 2019
Tracked Since Feb 18, 2026