CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778. |
2Debian Netkit2Debian Linux NetkitJun 17, 2026 Jan 31, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name...Show more |
3Debian FedoraprojectNetkit3Debian Linux FedoraNetkitJun 17, 2026 Jan 31, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory...Show more |
ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these...Show more |