Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-6097

Опубликовано: 10 сент. 2020
Источник: debian

Описание

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
atftpfixed0.7.git20120829-3.2package
atftpfixed0.7.git20120829-3.2~deb10u1busterpackage

Примечания

  • https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029

  • https://sourceforge.net/u/peterkaestle/atftp/ci/96409ef3b9ca061f9527cfaafa778105cf15d994/

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVSS3: 7.5
nvd
больше 5 лет назад

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

suse-cvrf
больше 5 лет назад

Security update for atftp

CVSS3: 7.5
github
больше 3 лет назад

An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.

CVSS3: 7.5
fstec
больше 5 лет назад

Уязвимость функции assert() сервера atftpd, связанная с ошибками освобождения ресурсов, позволяющая нарушителю вызвать отказ в обслуживании