mit krb5-appl CVE-2019-25018 is a vulnerability in MIT Krb5 Appl
Published on February 2, 2021

In the rcp client in MIT krb5-appl through 1.0.3, malicious servers could bypass intended access restrictions via the filename of . or an empty filename, similar to CVE-2018-20685 and CVE-2019-7282. The impact is modifying the permissions of the target directory on the client side. NOTE: MIT krb5-appl is not supported upstream but is shipped by a few Linux distributions. The affected code was removed from the supported MIT Kerberos 5 (aka krb5) product many years ago, at version 1.8.

NVD


Products Associated with CVE-2019-25018

Want to know whenever a new CVE is published for MIT Krb5 Appl? stack.watch will email you.

 

Exploit Probability

EPSS
0.06%
Percentile
18.35%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.