UBUNTU-CVE-2019-7283
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-7283
Summary:
Details: An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.
References: https://ubuntu.com/security/CVE-2019-7283, https://bugs.debian.org/920486, https://sintonen.fi/advisories/scp-client-multiple-vulnerabilities.txt, https://www.cve.org/CVERecord?id=CVE-2019-7283
Affected packages
Package
Name: netkit-rsh
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
