PT-2002-3108 · Atftp · Atftp
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2396
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
atftp versions 0.5 through 0.6
Description
A buffer overflow issue exists, potentially allowing local users to execute arbitrary code via a long argument to the -g option, if installed setuid or setgid.
Recommendations
For atftp versions 0.5 through 0.6, consider removing setuid or setgid installation to mitigate the risk of arbitrary code execution.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Atftp