Oval Definition:oval:com.ubuntu.xenial:def:2019113660000000
Revision Date:2019-04-20Version:1
Title:CVE-2019-11366 on Ubuntu 16.04 LTS (xenial) - medium.
Description:An issue was discovered in atftpd in atftp 0.7.1. It does not lock the thread_list_mutex mutex before assigning the current thread data structure. As a result, the daemon is vulnerable to a denial of service attack due to a NULL pointer dereference. If thread_data is NULL when assigned to current, and modified by another thread before a certain tftpd_list.c check, there is a crash when dereferencing current->next.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-11366
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND atftp package in xenial is affected and may need fixing.
  • BACK