USN-6334-1
Dashboard / Vulnerabilities / USN-6334-1
USN-6334-1
Summary: atftp vulnerabilities
Details: Peter Wang discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2020-6097) Andreas B. Mundt discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2021-41054) Johannes Krupp discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server and make the server to disclose /etc/group data. (CVE-2021-46671)
References: https://ubuntu.com/security/notices/USN-6334-1, https://ubuntu.com/security/CVE-2020-6097, https://ubuntu.com/security/CVE-2021-41054, https://ubuntu.com/security/CVE-2021-46671
Affected packages
Package
Name: atftp
Purl: pkg:deb/ubuntu/atftp?arch=source&distro=esm-apps%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
