HIGH
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1
Published Sep 10, 2020
7.5
HIGHCVSS 3.1
EPSS 2.15%
Description
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
Affected products
- Vendor n/a Product Atftpd Defaultn/a
- Version atftp 0.7.git20120829-3.1+b1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Atftpd | n/a |
|
Configuration 1
- 0.7.git20120829-3.1\+b1
Configuration 2
- 9.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00058.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00014.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029 x_refsource_MISCExploitTechnical DescriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00058.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2021/11/msg00014.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029 | x_refsource_MISCExploitTechnical DescriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published Sep 10, 2020
Updated Aug 4, 2024
Reserved Jan 7, 2020
Link CVE-2020-6097
CISA Vulnrichment
Updated n/a