kumquat-buildroot/package/atftp
Peter Korsgaard 5b36e91fda package/atftp: add security fix for CVE-2020-6097
Fixed the following security issue:

- CVE-2020-6097: An exploitable denial of service vulnerability exists in
  the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1.  A
  specially crafted sequence of RRQ-Multicast requests trigger an assert()
  call resulting in denial-of-service.  An attacker can send a sequence of
  malicious packets to trigger this vulnerability.

For more details, see the report:
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
2021-02-05 13:48:16 +01:00
..
0001-Makefile.am-link-against-libpthread-for-atftp.patch
0002-argz.h-fix-musl-compile-add-missing-defines.patch
0003-tftp.h-tftpd.h-fix-musl-compile-missing-include.patch
0004-Fix-for-DoS-issue-CVE-2020-6097.patch
atftp.hash
atftp.mk
Config.in