{"id":"CVE-2019-25017","details":"An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp implementation being derived from 1983 rcp, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned (only directory traversal attacks are prevented). A malicious rcp server (or Man-in-The-Middle attacker) can overwrite arbitrary files in the rcp client target directory. If recursive operation (-r) is performed, the server can manipulate subdirectories as well (for example, to overwrite the .ssh/authorized_keys file). This issue is similar to CVE-2019-6111 and CVE-2019-7283. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.","modified":"2026-07-08T19:50:36.089405Z","published":"2021-02-02T18:15:10.937Z","related":["SUSE-SU-2021:0527-1"],"references":[{"type":"REPORT","url":"https://bugzilla.suse.com/show_bug.cgi?id=1131109"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/krb5/krb5-appl","events":[{"introduced":"0"},{"last_affected":"a6c9e0baea1a1030241fe00b0431e5ab454c5fa3"}],"database_specific":{"cpe":"cpe:2.3:a:mit:krb5-appl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"1.0.3"}],"source":"CPE_RANGE"}}],"versions":["krb5-appl-1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-25017.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}