Linux TFTP didn't restrict users to tftpboot directory, allowing remote retrieval of files

Risk Level: High risk vulnerability  High

Check or Attack Name: LinTftp

Platforms: Linux, TFTP
Description:

Some older linux distributions did not correctly limit tftp access to the /tftpboot directory, allowing attackers to retrieve the passwd file as ../etc/passwd.

Remedy:

TFTP is rarely needed in most network configurations and should be disabled. If TFTP is required in your configuration, you should install a more recent version of the daemon or upgrade your OS's distribution.

References:

CERT Advisory CA-91.18, Active Internet tftp Attacks, http://www.cert.org/advisories/CA-91.18.Active.Internet.tftp.Attacks.html


X-Force Logo
Know Your Risks