options.c in atftp before 0.7.5 reads past the end of an array, and consequently discloses server-side /etc/group data to a remote client.
{ "binaries": [ { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1~0.16.04.1+esm1", "binary_name": "atftpd" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1~0.18.04.1+esm1", "binary_name": "atftpd" } ], "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro" }
{ "binaries": [ { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftp" }, { "binary_version": "0.7.git20120829-3.1ubuntu0.1", "binary_name": "atftpd" } ], "availability": "No subscription required" }