CVE-2019-7283 -- rsh-serverID: oval:org.secpod.oval:def:1900001 | Date: (C)2019-03-22 (M)2023-12-20 |
Class: VULNERABILITY | Family: unix |
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server can overwrite arbitrary files in a directory on the rcp clientmachine. This is similar to CVE-2019-6111.
Platform: |
Ubuntu 16.04 |
Ubuntu 18.10 |
Ubuntu 14.04 |
Ubuntu 18.04 |