vendor:
Tftpd32
by:
Bug Description
5
CVSS
MEDIUM
Denial Of Service
N/A
CWE
Product Name: Tftpd32
Affected Version From: v4.00
Affected Version To: v4.00
Patch Exists: YES
Related CWE: N/A
CPE: tftpd32.jounin.net
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2012
Tftpd32 DNS Server Denial Of Service Vulnerability
Tftpd32 is a free tftp and dns server for windows, freeware tftp server. And the dns server would bind udp port 53, but it does not validate the domain option size leading to a Denial Of Service flaw while sending more than 127 characters to it.
Mitigation:
The tftpd32's dns server can drop the evil request when it was detected the domain option size were longer than 127 characters.