CVE-2019-7282
Summary
| CVE | CVE-2019-7282 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-31 18:29:00 UTC |
| Updated | 2023-11-07 03:13:00 UTC |
| Description | In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Operating System | Fedoraproject | Fedora | 36 | All | All | All |
| Application | Netkit | Netkit | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2822-1] netkit-rsh security update | MLIST | lists.debian.org | |
| [SECURITY] Fedora 36 Update: rsh-0.17-101.fc36 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 35 Update: rsh-0.17-100.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| 503 Backend fetch failed | FEDORA | lists.fedoraproject.org | |
| #920486 - netkit-rsh: CVE-2019-7282 CVE-2019-7283 - Debian Bug report logs | MISC | bugs.debian.org | Exploit, Issue Tracking, Vendor Advisory |
| [SECURITY] Fedora 34 Update: rsh-0.17-98.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| 503 Backend fetch failed | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 36 Update: rsh-0.17-101.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt | MISC | sintonen.fi | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 178904 Debian Security Update for netkit-rsh (DLA 2822-1)
- 198701 Ubuntu Security Notification for rsh Vulnerability (USN-5327-1)
- 282538 Fedora Security Update for rsh (FEDORA-2022-82a6236ac7)
- 282539 Fedora Security Update for rsh (FEDORA-2022-6748ae617b)
- 671900 EulerOS Security Update for rsh (EulerOS-SA-2022-1949)