First published: Wed Jun 28 2023(Updated: )
netkit-rcp in rsh-client 0.17-24 allows command injection via filenames because /bin/sh is used by susystem, a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netkit | =0.17-24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-38336 is considered a high severity vulnerability due to its potential for command injection.
To fix CVE-2023-38336, update the rsh-client package to a version that has addressed the vulnerability.
CVE-2023-38336 affects the rsh-client version 0.17-24 of the Netkit software.
CVE-2023-38336 is a command injection vulnerability that arises from improper handling of filenames.
Yes, CVE-2023-38336 is a related issue to CVE-2006-0225, CVE-2019-7283, and CVE-2020-15778.