TFTP.Filename.Format.String

description-logoDescription

A vulnerability has been identified in TFTPD32, which could be exploited by attackers to cause a denial of service or execute arbitrary commands. This flaw is due to a format string error when processing a specially crafted GET request containing a malformed filename, which could be exploited by attackers to crash a vulnerable application and possibly execute arbitrary code.

affected-products-logoAffected Products

TFTPD32 version 2.81 and prior.

Impact logoImpact

Denial of service

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patches for this issue.
http://tftpd32.jounin.net/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-04-13 18.057 Sig Added