An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.
2019-01-31T18:29:00.977
2024-11-21T04:47:55.393
Modified
CVSSv3.1: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:N/I:P/A:P
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netkit | netkit | ≤ 0.17 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |