- -------------------------------------------------------------------------
Debian LTS Advisory DLA-2820-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                    Thorsten Alteholz
November 17, 2021                             https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : atftp
Version        : 0.7.git20120829-3.1~deb9u2
CVE ID         : CVE-2020-6097 CVE-2021-41054


Two issues have been found in atftp, an advanced TFTP client.
Both are related to sending crafted requests to the server and triggering 
a denial-of-service due to for example a buffer overflow.


For Debian 9 stretch, these problems have been fixed in version
0.7.git20120829-3.1~deb9u2.

We recommend that you upgrade your atftp packages.

For the detailed security status of atftp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/atftp

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-2820-1: atftp security update

November 16, 2021
Two issues have been found in atftp, an advanced TFTP client

Summary

Two issues have been found in atftp, an advanced TFTP client.
Both are related to sending crafted requests to the server and triggering
a denial-of-service due to for example a buffer overflow.


For Debian 9 stretch, these problems have been fixed in version
0.7.git20120829-3.1~deb9u2.

We recommend that you upgrade your atftp packages.

For the detailed security status of atftp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/atftp

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : atftp
Version : 0.7.git20120829-3.1~deb9u2
CVE ID : CVE-2020-6097 CVE-2021-41054

Related News