← Back

Netkit

netkit

7 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Netkit
netkit
Linux Netkit
linux_netkit

CVEs (7)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netkit
1Netkit
Jun 17, 2026
Jul 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
2Debian
Netkit
2Debian Linux
Netkit
Jun 17, 2026
Jan 31, 2019
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name...Show more
An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111.Show less
3Debian
FedoraprojectNetkit
3Debian Linux
FedoraNetkit
Jun 17, 2026
Jan 31, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory...Show more
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.Show less
1Netkit
1Netkit
Apr 23, 2026
Nov 21, 2006
N/A· v4
N/A· v3
6.5 MEDIUM· v2
ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these...Show more
ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as PAM failures or resource limits, a different vulnerability than CVE-2006-5778.Show less
3Linux
NetkitVserver
3Linux Vserver
Linux KernelLinux Netkit
Apr 16, 2026
Mar 7, 2005
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Race condition in the setsid function in Linux before 2.6.8.1 allows local users to cause a denial of service (crash) and possibly access portions of kernel memory, related to TTY changes, locking, and semaphores.
2Netkit
Ssltelnetd
2Linux Netkit
Secure Telnet
Apr 16, 2026
Aug 6, 2004
N/A· v4
N/A· v3
10.0 HIGH· v2
Format string vulnerability in the SSL_set_verify function in telnetd.c for SSLtelnet daemon (SSLtelnetd) 0.13 allows remote attackers to execute arbitrary code.
9Debian
FreebsdIbm+6 more
11Aix
Debian LinuxFreebsd+8 more
Apr 16, 2026
Aug 14, 2001
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by t...Show more
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbitrary commands via a set of options including AYT (Are You There), which is not properly handled by the telrcv function.Show less