Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
172

Ubuntu 23.04 Security Notice: 6375-1 atftp Denial of Service Vulnerability

atftp could be made to crash if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-6375-1 September 15, 2023 atftp vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS Summary: atftp could be made to crash if it received specially crafted network traffic. Software Description: - atftp: Advanced TFTP Server and Client Details: Florian Fainelli discovered that atftp did not properly manage requests made to a non-existent file, which could lead to a crash. A remote attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: atftpd 0.8.0-3build0.23.04.1 Ubuntu 22.04 LTS: atftpd 0.7.git20210915-4build1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6375-1 https://bugs.launchpad.net/ubuntu/+source/atftp/+bug/1989816 Package Information: https://launchpad.net/ubuntu/+source/atftp/0.8.0-3build0.23.04.1 https://launchpad.net/ubuntu/+source/atftp/0.7.git20210915-4build1 . A critical vulnerability in the atftp package on Ubuntu may allow remote attackers to trigger a denial of service. Users should apply patches urgently. atftp vulnerability, Ubuntu security update, denial of service, remote exploit, critical advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 15, 2023 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-6334-1 Critical: atftp Input Flaws and Exploits

Several security issues were fixed in atftp.. ========================================================================== Ubuntu Security Notice USN-6334-1 September 04, 2023 atftp vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in atftp. Software Description: - atftp: Advanced TFTP Server and Client Details: Peter Wang discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2020-6097) Andreas B. Mundt discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server to cause a crash. (CVE-2021-41054) Johannes Krupp discovered that atftp did not properly manage certain inputs. A remote attacker could send a specially crafted tftp request to the server and make the server to disclose /etc/group data. (CVE-2021-46671) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: atftpd 0.7.git20120829-3.1ubuntu0.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): atftpd 0.7.git20120829-3.1~0.18.04.1+esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): atftpd 0.7.git20120829-3.1~0.16.04.1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6334-1 CVE-2020-6097, CVE-2021-41054, CVE-2021-46671 Package Information: https://launchpad.net/ubuntu/+source/atftp/0.7.git20120829-3.1ubuntu0.1 . A number of security flaws in atftp have been identified, impacting various Ubuntu LTS versions, along withdetailed remediation steps provided.. atftp Vulnerabilities, Ubuntu Update, Remote Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 04, 2023 Critical Ubuntu
197

Debian LTS: DLA-3028-1 atftp Buffer Overrun Risk Advisory

An issue has been found in package atftp, an advanced TFTP client/server. Due to missing bound checks, data could be read behind a buffer so that . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3028-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz May 27, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : atftp Version : 0.7.git20120829-3.1~deb9u3 CVE ID : CVE-2021-46671 An issue has been found in package atftp, an advanced TFTP client/server. Due to missing bound checks, data could be read behind a buffer so that sensible information might be disclosed to a remote client. For Debian 9 stretch, this problem has been fixed in version 0.7.git20120829-3.1~deb9u3. We recommend that you upgrade your atftp packages. For the detailed security status of atftp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/atftp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This advisory highlights a vulnerability in the atftp package on Debian LTS, risking remote disclosure of sensitive information under specific conditions. Debian LTS, atftp Security, Remote Data Disclosure, Security Patch, Buffer Overflow. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 26, 2022 Important Debian LTS
100

SUSE: 2022:0881-1 Minor Issue: atftp Data Exposure Patch

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for atftp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0881-1 Rating: low References: #1195619 Cross-References: CVE-2021-46671 CVSS scores: CVE-2021-46671 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2021-46671 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for atftp fixes the following issues: - CVE-2021-46671: Fixed a potential information leak in atftpd (bsc#1195619). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2022-881=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): atftp-0.7.0-160.14.1 atftp-debuginfo-0.7.0-160.14.1 atftp-debugsource-0.7.0-160.14.1 References: https://www.suse.com/security/cve/CVE-2021-46671.html https://bugzilla.suse.com/1195619 . The latest atftp update addresses a minor information leak vulnerability classified as low severity. Refer to the patch instructions for steps on how to apply the fix.. SUSE Linux Enterprise, atftp update, security patch, information leak. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Mar 16, 2022 Low SuSE
197

Debian 9: DLA-2820-1 Moderate: Atftp Buffer Overflow Threat

Two issues have been found in atftp, an advanced TFTP client. Both are related to sending crafted requests to the server and triggering a denial-of-service due to for example a buffer overflow. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2820-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz November 17, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : atftp Version : 0.7.git20120829-3.1~deb9u2 CVE ID : CVE-2020-6097 CVE-2021-41054 Two issues have been found in atftp, an advanced TFTP client. Both are related to sending crafted requests to the server and triggering a denial-of-service due to for example a buffer overflow. For Debian 9 stretch, these problems have been fixed in version 0.7.git20120829-3.1~deb9u2. We recommend that you upgrade your atftp packages. For the detailed security status of atftp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/atftp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2821-1 outlines vulnerabilities in the package libxml2, addressing critical memory corruption flaws and providing fixes to enhance stability and security.. Debian LTS, atftp, denial of service, security update. . LinuxSecurity.com Team

Calendar 2 Nov 16, 2021 Debian LTS
100

SUSE: 2021:3240-2 Moderate Security Patch for ntfs-3g Vulnerability

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for atftp ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3237-1 Rating: moderate References: #1190522 Cross-References: CVE-2021-41054 CVSS scores: CVE-2021-41054 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for atftp fixes the following issues: - CVE-2021-41054: Fixed buffer overflow caused by combination of data, OACK, and other options (bsc#1190522). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-3237=1 Package List: - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): atftp-0.7.0-160.11.1 atftp-debuginfo-0.7.0-160.11.1 atftp-debugsource-0.7.0-160.11.1 References: https://www.suse.com/security/cve/CVE-2021-41054.html https://bugzilla.suse.com/1190522 . The latest SUSE Security Update addresses a critical buffer overflow vulnerability in atftp. Advisory ID: SUSE-SU-2021:3245-1. SUSE Linux Enterprise, atftp security update, software vulnerability fix. . LinuxSecurity.com Team

Calendar 2 Sep 27, 2021 SuSE
198

Ubuntu Security Notice: USN-4500-1 Critical: python3.8 Vulnerability

The package atftp before version 0.7.2-3 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-202101-24 ========================================= Severity: Medium Date : 2021-01-12 CVE-ID : CVE-2020-6097 Package : atftp Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-1395 Summary ====== The package atftp before version 0.7.2-3 is vulnerable to denial of service. Resolution ========= Upgrade to 0.7.2-3. # pacman -Syu "atftp> =0.7.2-3" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.2. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability. Impact ===== A malicious remote user might crash the application by performing a sequence of crafted queries. References ========= https://bugs.archlinux.org/task/69175 https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029 https://security.archlinux.org/CVE-2020-6097 . The security notice for Arch Linux, ASA-202102-48, informs users of a moderate risk buffer overflow vulnerability found in the package xyztool, which affects versions before 1.4.1-2.. Arch Linux, atftp, denial of service, security advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jan 15, 2021 Medium ArchLinux
172

Ubuntu 16.04 LTS USN-4643-1 Critical: atftp Denial Of Service Issue

atftp could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4643-1 November 24, 2020 atftp vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: atftp could be made to crash or run programs if it received specially crafted network traffic. Software Description: - atftp: Advanced TFTP Server and Client Details: It was discovered that atftp's FTP server did not properly handler certain input. An attacker could use this to to cause a denial of service (crash) or possibly execute arbitrary code. (CVE-2019-11365) It was discovered that atftp's FTP server did not make proper use of mutexes when locking certain data structures. An attacker could use this to cause a denial of service via a NULL pointer dereference. (CVE-2019-11366) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: atftp 0.7.git20120829-3.1~0.16.04.1 atftpd 0.7.git20120829-3.1~0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4643-1 CVE-2019-11365, CVE-2019-11366 Package Information: https://launchpad.net/ubuntu/+source/atftp/0.7.git20120829-3.1~0.16.04.1 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . Debian reveals significant security concerns linked to nfs-utils flaws within their 9.0 Stretch release, necessitating immediate patches.. Ubuntu 16.04, atftp update, network risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 24, 2020 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here