An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequence of RRQ-Multicast requests trigger an assert() call resulting in denial-of-service. An attacker can send a sequence of malicious packets to trigger this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| atftp_project / atftp | 0.7.git20120829-3.1+b1 | 0.7.git20120829-3.1+b1.x |
| debian / debian_linux | 9.0 | 9.0.x |
| opensuse / leap | 15.2 | 15.2.x |