Netkit

Netkit

4 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.73%
  • Published 14.07.2023 22:15:09
  • Last modified 21.11.2024 08:13:22

netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.

Exploit
  • EPSS 0.88%
  • Published 31.01.2019 18:29:00
  • Last modified 21.11.2024 04:47:55

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is s...

Exploit
  • EPSS 0.2%
  • Published 31.01.2019 18:29:00
  • Last modified 21.11.2024 04:47:55

An issue was discovered in rcp in NetKit through 0.17. For an rcp operation, the server chooses which files/directories are sent to the client. However, the rcp client only performs cursory validation of the object name returned. A malicious rsh serv...

  • EPSS 1.14%
  • Published 21.11.2006 23:07:00
  • Last modified 09.04.2025 00:30:58

ftpd in Linux Netkit (linux-ftpd) 0.17, and possibly other versions, does not check the return status of certain seteuid, setgid, and setuid calls, which might allow remote authenticated users to gain privileges if these calls fail in cases such as P...