Skip to content

Conversation

@bagder
Copy link
Member

@bagder bagder commented Sep 21, 2025

Store the used remote address on the first receive call and then make sure that it remains the same address on subsequent calls to reduce the risk of tampering. Doesn't make the transfer secure because it is still unauthenticated and clear text.

Reported in Joshua's sarif data

Store the used remote address on the first receive call and then make
sure that it remains the same address on subsequent calls to reduce the
risk of tampering. Doesn't make the transfer secure because it is still
unauthenticated and clear text.

Reported in Joshua's sarif data
@bagder bagder added the TFTP label Sep 21, 2025
@bagder bagder marked this pull request as ready for review September 21, 2025 09:11
@bagder bagder closed this in c4f9977 Sep 21, 2025
@bagder bagder deleted the bagder/tftp-pin-address branch September 21, 2025 21:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Development

Successfully merging this pull request may close these issues.

1 participant