{"id":"MGASA-2021-0525","summary":"Updated rsh packages fix security vulnerability","details":"In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers\nto bypass intended access restrictions via the filename of . or an empty\nfilename. The impact is modifying the permissions of the target directory\non the client side. This is similar to CVE-2018-20685. (CVE-2019-7282)\n\nAn issue was discovered in rcp in NetKit through 0.17. For an rcp\noperation, the server chooses which files/directories are sent to the\nclient. However, the rcp client only performs cursory validation of the\nobject name returned. A malicious rsh server (or Man-in-The-Middle\nattacker) can overwrite arbitrary files in a directory on the rcp client\nmachine. This is similar to CVE-2019-6111. (CVE-2019-7283).\n","modified":"2026-04-16T04:41:30.100682445Z","published":"2021-11-25T13:06:13Z","upstream":["CVE-2019-7282","CVE-2019-7283"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2021-0525.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29675"},{"type":"WEB","url":"https://www.debian.org/lts/security/2021/dla-2822"}],"affected":[{"package":{"name":"rsh","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/rsh?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.17-36.1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2021-0525.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}