vendor:
atftp
by:
Julien LANTHEA
7.2
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: atftp
Affected Version From: 0.7cvs
Affected Version To: 0.7cvs
Patch Exists: YES
Related CWE: N/A
CPE: atftp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: RedHat 8
2003
atftp Local Buffer Overflow Vulnerability
atftp is prone to a locally exploitable buffer overflow condition. This issue is due to insufficient bounds checking performed on input supplied to the command line parameter (-t) for 'timeout'. Local attackers may exploit this condition to execute arbitrary instructions. It should be noted that although this vulnerability has been reported to affect atftp version 0.7cvs, other versions might also be vulnerable.
Mitigation:
Upgrade to the latest version of atftp.