An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "atftp", "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1" }, { "binary_name": "atftp-dbgsym", "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1" }, { "binary_name": "atftpd", "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1" }, { "binary_name": "atftpd-dbgsym", "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "binaries": [ { "binary_name": "atftp", "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1" }, { "binary_name": "atftp-dbgsym", "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1" }, { "binary_name": "atftpd", "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1" }, { "binary_name": "atftpd-dbgsym", "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "atftp", "binary_version": "0.7.git20120829-3.1ubuntu0.1" }, { "binary_name": "atftp-dbgsym", "binary_version": "0.7.git20120829-3.1ubuntu0.1" }, { "binary_name": "atftpd", "binary_version": "0.7.git20120829-3.1ubuntu0.1" }, { "binary_name": "atftpd-dbgsym", "binary_version": "0.7.git20120829-3.1ubuntu0.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "atftp", "binary_version": "0.7.git20210915-4" }, { "binary_name": "atftp-dbgsym", "binary_version": "0.7.git20210915-4" }, { "binary_name": "atftpd", "binary_version": "0.7.git20210915-4" }, { "binary_name": "atftpd-dbgsym", "binary_version": "0.7.git20210915-4" } ] }