{"id":"MGASA-2021-0196","summary":"Updated krb5-appl packages fix security vulnerabilities","details":"An issue was discovered in rcp in MIT krb5-appl through 1.0.3. Due to the rcp\nimplementation being derived from 1983 rcp, the server chooses which\nfiles/directories are sent to the client. However, the rcp client only\nperforms cursory validation of the object name returned (only directory\ntraversal attacks are prevented). A malicious rcp server (or\nMan-in-The-Middle attacker) can overwrite arbitrary files in the rcp client\ntarget directory. If recursive operation (-r) is performed, the server can\nmanipulate subdirectories as well (for example, to overwrite the\n.ssh/authorized_keys file). This issue is similar to CVE-2019-6111 and\nCVE-2019-7283 (CVE-2019-25017).\n\nIn the rcp client in MIT krb5-appl through 1.0.3 malicious servers could\nbypass intended access restrictions via the filename of . or an empty\nfilename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying\nthe permissions of the target directory on the client side (CVE-2019-25018).\n","modified":"2026-04-16T04:40:38.584210960Z","published":"2021-04-23T22:53:14Z","upstream":["CVE-2019-25017","CVE-2019-25018"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0196.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=28460"},{"type":"WEB","url":"https://lists.suse.com/pipermail/sle-security-updates/2021-February/008353.html"}],"affected":[{"package":{"name":"krb5-appl","ecosystem":"Mageia:7","purl":"pkg:rpm/mageia/krb5-appl?arch=source&distro=mageia-7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3-10.2.mga7"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0196.json"}},{"package":{"name":"krb5-appl","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/krb5-appl?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.3-13.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0196.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}