CVE-2021-41054Classic Buffer Overflow in Project Atftp

Severity
7.5HIGHNVD
EPSS
0.5%
top 34.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateSep 4

Description

tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data, OACK, and other options.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

Debianatftp_project/atftp< 0.7.git20120829-3.3+deb11u1+3
Ubuntuatftp_project/atftp< 0.7.git20120829-3.1ubuntu0.1+2

Also affects: Debian Linux 9.0

Patches

🔴Vulnerability Details

4
OSV
atftp vulnerabilities2023-09-04
GHSA
GHSA-pjhr-q582-mpq7: tftpd_file2022-05-24
OSV
CVE-2021-41054: tftpd_file2021-09-13
CVEList
CVE-2021-41054: tftpd_file2021-09-13

📋Vendor Advisories

3
Ubuntu
atftp vulnerabilities2023-09-04
Microsoft
tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size handling does not properly consider the combination of data OACK and other options.2021-09-14
Debian
CVE-2021-41054: atftp - tftpd_file.c in atftp through 0.7.4 has a buffer overflow because buffer-size ha...2021
CVE-2021-41054 — Classic Buffer Overflow | cvebase