PT-2019-6235 · Netkit · Netkit

Published

2019-01-26

·

Updated

2023-07-15

·

CVE-2019-7283

CVSS v2.0

8.8

High

VectorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetKit versions through 0.17
Description The issue allows a malicious rsh server or a Man-in-The-Middle attacker to overwrite arbitrary files in a directory on the rcp client machine due to the rcp client only performing cursory validation of the object name returned by the server. This can lead to data integrity compromise and potentially cause a denial of service.
Recommendations For NetKit versions through 0.17, as a temporary workaround, consider restricting access to the rcp operation until a patch is available. Additionally, restrict the use of the rsh server to trusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2022-05872
CVE-2019-7283
DLA-2822-1
MGASA-2021-0525

Affected Products

Netkit