FS#69175 - [atftp] [Security] denial of service (CVE-2020-6097)

Attached to Project: Community Packages
Opened by Jonas Witschel (diabonas) - Friday, 01 January 2021, 23:19 GMT
Last edited by Christian Hesse (eworm) - Friday, 01 January 2021, 23:37 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Christian Hesse (eworm)
Levente Polyak (anthraxx)
Architecture All
Severity Medium
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Summary
=======

The package atftp is vulnerable to denial of service via CVE-2020-6097.

Guidance
========

Applying commit 96409ef3b9ca061f9527cfaafa778105cf15d994 referenced below fixes the issue.

References
==========

https://security.archlinux.org/AVG-1395
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029
https://sourceforge.net/u/peterkaestle/atftp/ci/96409ef3b9ca061f9527cfaafa778105cf15d994/
This task depends upon

Closed by  Christian Hesse (eworm)
Friday, 01 January 2021, 23:37 GMT
Reason for closing:  Fixed
Additional comments about closing:  atftp 0.7.2-3

Loading...