tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftp-dbgsym" }, { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftpd" }, { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftpd-dbgsym" } ] }
{ "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftp-dbgsym" }, { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftpd" }, { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftpd-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftp-dbgsym" }, { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftpd" }, { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftpd-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "0.7.git20210915-4", "binary_name": "atftp" }, { "binary_version": "0.7.git20210915-4", "binary_name": "atftp-dbgsym" }, { "binary_version": "0.7.git20210915-4", "binary_name": "atftpd" }, { "binary_version": "0.7.git20210915-4", "binary_name": "atftpd-dbgsym" } ] }