PT-2019-6235 · Netkit · Netkit

CVE-2019-7283

·

Publicado

2019-01-26

·

Atualizado

2023-07-15

CVSS v2.0

8.8

Alta

VetorAV:N/AC:M/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions NetKit versions through 0.17
Description The issue allows a malicious rsh server or a Man-in-The-Middle attacker to overwrite arbitrary files in a directory on the rcp client machine due to the rcp client only performing cursory validation of the object name returned by the server. This can lead to data integrity compromise and potentially cause a denial of service.
Recommendations For NetKit versions through 0.17, as a temporary workaround, consider restricting access to the rcp operation until a patch is available. Additionally, restrict the use of the rsh server to trusted sources to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2022-05872
CVE-2019-7283
DLA-2822-1
MGASA-2021-0525

Produtos afetados

Netkit