CVE-2019-7282: Debian Linux

Medium severity, CVSS 5.9. EPSS: 2.1% chance of exploitation in the next 30 days.

In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 34 only; version 35 only; version 36 only
  • Netkit Netkit: up to and including 0.17

Published 2019-01-31. Last modified 2026-06-17.