CVE-2019-7282
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
- Netkit
- ≤ 0.17
- Fix
- Available
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 2.1% (80th percentile)
- NVD status
- Modified
- Published
- 2019-01-31
CVE-2019-7282 at NVD
No indexed exploits for CVE-2019-7282 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-7282 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.