package/atftp: add security fix for CVE-2020-6097
authorPeter Korsgaard <peter@korsgaard.com>
Fri, 5 Feb 2021 09:01:01 +0000 (10:01 +0100)
committerYann E. MORIN <yann.morin.1998@free.fr>
Fri, 5 Feb 2021 12:48:16 +0000 (13:48 +0100)
commit5b36e91fda95de313120ab530a07329a1c5d41db
treeb8e983540c3f1a30cc880676e146a5cc83647c6e
parentb5aab68465e4b3174a2f7975d5f3ccfa587db62a
package/atftp: add security fix for CVE-2020-6097

Fixed the following security issue:

- CVE-2020-6097: An exploitable denial of service vulnerability exists in
  the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1.  A
  specially crafted sequence of RRQ-Multicast requests trigger an assert()
  call resulting in denial-of-service.  An attacker can send a sequence of
  malicious packets to trigger this vulnerability.

For more details, see the report:
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1029

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
Signed-off-by: Yann E. MORIN <yann.morin.1998@free.fr>
package/atftp/0004-Fix-for-DoS-issue-CVE-2020-6097.patch [new file with mode: 0644]
package/atftp/atftp.mk