Thread (3 messages) 3 messages, 2 authors, 2021-02-10

[Buildroot] [PATCH] package/atftp: add security fix for CVE-2020-6097

From: Peter Korsgaard <peter@korsgaard.com>
Date: 2021-02-10 18:55:31

quoted
quoted
quoted
quoted
"Peter" == Peter Korsgaard [off-list ref] writes:
 > Fixed the following security issue:
 > - CVE-2020-6097: An exploitable denial of service vulnerability exists in
 >   the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1.  A
 >   specially crafted sequence of RRQ-Multicast requests trigger an assert()
 >   call resulting in denial-of-service.  An attacker can send a sequence of
 >   malicious packets to trigger this vulnerability.

 > For more details, see the report:
 > https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029

 > Signed-off-by: Peter Korsgaard [off-list ref]

Committed to 2020.02.x and 2020.11.x, thanks.

-- 
Bye, Peter Korsgaard
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help