PT-2019-2187 · Atftp+3 · Atftp+3

Denis Andzakovic

·

Published

2019-04-14

·

Updated

2022-09-14

·

CVE-2019-11366

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions atftp version 0.7.1
Description The issue is related to the thread list mutex mutex in the atftpd component of atftp. It does not properly lock the mutex before assigning the current thread data structure, leading to a potential denial of service attack due to a NULL pointer dereference. If thread data is NULL when assigned to current, and modified by another thread before a certain check in tftpd list.c, there is a crash when dereferencing current->next. This allows a remote attacker to cause a denial of service.
Recommendations For atftp version 0.7.1, consider applying a patch that properly locks the thread list mutex mutex before assigning the current thread data structure to prevent the NULL pointer dereference. As a temporary workaround, consider restricting access to the atftpd service to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3133
ALT-PU-2020-3153
ALT-PU-2022-2609
BDU:2019-01954
CVE-2019-11366
DLA-1783-1
DSA-4438-1
SUSE-SU-2019:1091-1
SUSE-SU-2019:14033-1
SUSE-SU-2019_14033-1
USN-4540-1
USN-4643-1

Affected Products

Alt Linux
Suse
Ubuntu
Atftp