Bug#920486: rsh-client: rcp has CVE-2018-20685 similar to scp

2019-01-28 Thread Hiroyuki YAMAMORI
From: Alberto Gonzalez Iniesta Date: Mon, 28 Jan 2019 16:46:21 +0100 > On Sat, Jan 26, 2019 at 02:20:06PM +0900, Hiroyuki YAMAMORI wrote: >> Package: rsh-client >> Version: 0.17-19 >> Severity: important >> Tags: security >> >> Refer Bug #919101 >> >> Dear Maintainer, >> >> netkit-rcp also has

Bug#920486: rsh-client: rcp has CVE-2018-20685 similar to scp

2019-01-28 Thread Alberto Gonzalez Iniesta
On Sat, Jan 26, 2019 at 02:20:06PM +0900, Hiroyuki YAMAMORI wrote: > Package: rsh-client > Version: 0.17-19 > Severity: important > Tags: security > > Refer Bug #919101 > > Dear Maintainer, > > netkit-rcp also has CVE-2018-20685 and CVE-2019-6111 similar to scp. Hi! Thanks for noticing. Attac

Bug#920486: rsh-client: rcp has CVE-2018-20685 similar to scp

2019-01-25 Thread Hiroyuki YAMAMORI
Package: rsh-client Version: 0.17-19 Severity: important Tags: security Refer Bug #919101 Dear Maintainer, netkit-rcp also has CVE-2018-20685 and CVE-2019-6111 similar to scp. Source code of the problem below: "netkit-rsh-0.17/rcp/rcp.c" line 750 (after debian patched) while (i