Vulnerability Description
Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP error packet, a different vulnerability than CVE-2018-10387 and CVE-2019-12568.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Tftp Server Project | Open Tftp Server | <= 1.65 |
Related Weaknesses (CWE)
References
- https://sourceforge.net/p/tftp-server/discussion/550564/thread/a586ce62/PatchThird Party Advisory
- https://sourceforge.net/p/tftp-server/discussion/550564/thread/a586ce62/PatchThird Party Advisory
FAQ
What is CVE-2019-12567?
CVE-2019-12567 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Stack-based overflow vulnerability in the logMess function in Open TFTP Server MT 1.65 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via a long TFTP erro...
How severe is CVE-2019-12567?
CVE-2019-12567 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-12567?
Check the references section above for vendor advisories and patch information. Affected products include: Open Tftp Server Project Open Tftp Server.