phjounin TFTPD64 Denial-of-Service Vulnerability in DNS Handler

Vulnerability

A denial-of-service vulnerability has been identified in phjounin TFTPD64 version 4.64, the latest release. This issue arises in the DNS Handler component, where the application can be made to terminate unexpectedly. The vulnerability is triggered by sending a large DNS request, similar to the one provided in a proof-of-concept script available on GitHub. This exploitation needs to be performed within the local network, and the complexity of the attack is considered high.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition, causing the application to crash.

Reproduction

The vulnerability can be reproduced by sending a crafted DNS request that exceeds 132 bytes to the application while it is running. This can be done using the proof-of-concept Python script available in the GitHub repository 'DMCERTCE/TFTPD64_DOS'. The script sends the oversized DNS query to the local instance of TFTPD64, causing the application to terminate.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.