USN-4643-1
Dashboard / Vulnerabilities / USN-4643-1
USN-4643-1
Summary: atftp vulnerabilities
Details: It was discovered that atftp's FTP server did not properly handler certain input. An attacker could use this to to cause a denial of service (crash) or possibly execute arbitrary code. (CVE-2019-11365) It was discovered that atftp's FTP server did not make proper use of mutexes when locking certain data structures. An attacker could use this to cause a denial of service via a NULL pointer dereference. (CVE-2019-11366)
References: https://ubuntu.com/security/notices/USN-4643-1, https://ubuntu.com/security/CVE-2019-11365, https://ubuntu.com/security/CVE-2019-11366
Affected packages
Package
Name: atftp
Purl: pkg:deb/ubuntu/[email protected]~0.16.04.1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
