MGASA-2021-0525

Source
https://advisories.mageia.org/MGASA-2021-0525.html
Import Source
https://advisories.mageia.org/MGASA-2021-0525.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2021-0525
Upstream
Published
2021-11-25T13:06:13Z
Modified
2026-04-16T04:41:30.100682445Z
Summary
Updated rsh packages fix security vulnerability
Details

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685. (CVE-2019-7282)

An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh server (or Man-in-The-Middle attacker) can overwrite arbitrary files in a directory on the rcp client machine. This is similar to CVE-2019-6111. (CVE-2019-7283).

References
Credits

Affected packages

Mageia:8 / rsh

Package

Name
rsh
Purl
pkg:rpm/mageia/rsh?arch=source&distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.17-36.1.mga8

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2021-0525.json"