---
title: "CVE-2019-11366\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-11366?format=md
keywords: index, follow
---

# CVE-2019-11366

Publication date 20 April 2019

Last updated 25 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.9 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-11366?format=md#impact-score)

Toggle side navigation

## Description

An issue was discovered in atftpd in atftp 0.7.1. It does not lock the
thread\_list\_mutex mutex before assigning the current thread data structure.
As a result, the daemon is vulnerable to a denial of service attack due to
a NULL pointer dereference. If thread\_data is NULL when assigned to
current, and modified by another thread before a certain tftpd\_list.c
check, there is a crash when dereferencing current->next.

### From the Ubuntu Security Team

It was discovered that atftp's FTP server did not make proper use of mutexes
when locking certain data structures. An attacker could use this to cause a
denial of service via a NULL pointer dereference.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| atftp | 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Not affected |
| 19.04 disco | Ignored end of life |
| 18.10 cosmic | Ignored end of life |
| 18.04 LTS bionic | Fixed 0.7.git20120829-3.1~0.18.04.1 |
| 16.04 LTS xenial | Fixed 0.7.git20120829-3.1~0.16.04.1 |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.9 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | High |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.9 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11366)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-11366)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-11366)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-11366)

### Related Ubuntu Security Notices (USN)

+ [USN-4540-1](https://usn.ubuntu.com/USN-4540-1)
+ atftpd vulnerabilities
+ 24 September 2020

+ [USN-4643-1](https://usn.ubuntu.com/USN-4643-1)
+ atftp vulnerabilities
+ 24 November 2020

### Other references

* <https://pulsesecurity.co.nz/advisories/atftpd-multiple-vulnerabilities>
* <https://sourceforge.net/p/atftp/code/ci/382f76a90b44f81fec00e2f609a94def4a5d3580/>
* <https://www.cve.org/CVERecord?id=CVE-2019-11366>
