First published: Mon Sep 04 2023(Updated: )
Peter Wang discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2020-6097) Andreas B. Mundt discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2021-41054) Johannes Krupp discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server and make the server to disclose /etc/group data. (CVE-2021-46671)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/atftpd | <0.7.git20120829-3.1ubuntu0.1 | 0.7.git20120829-3.1ubuntu0.1 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/atftpd | <0.7.git20120829-3.1~0.18.04.1+esm1 | 0.7.git20120829-3.1~0.18.04.1+esm1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/atftpd | <0.7.git20120829-3.1~0.16.04.1+esm1 | 0.7.git20120829-3.1~0.16.04.1+esm1 |
Ubuntu Ubuntu | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
CVE-2020-6097
By sending a specially crafted tftp request to the server.
0.7.git20120829-3.1ubuntu0.1
0.7.git20120829-3.1~0.18.04.1+esm1
0.7.git20120829-3.1~0.16.04.1+esm1