CVE-2018-17580

CWE-125Out-of-bounds Read10 documents7 sources
Severity
7.1HIGH
EPSS
0.2%
top 56.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 28
Latest updateOct 4

Description

A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial of Service (DoS) and potentially Information Exposure when the application attempts to process a crafted pcap file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

Debiantcpreplay< 4.3.1-1+3

Patches

🔴Vulnerability Details

4
OSV
tcpreplay vulnerabilities2022-10-04
GHSA
GHSA-9qr2-28pv-9m9x: A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets2022-05-13
CVEList
CVE-2018-17580: A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets2018-09-28
OSV
CVE-2018-17580: A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets2018-09-28

📋Vendor Advisories

2
Ubuntu
Tcpreplay vulnerabilities2022-10-04
Debian
CVE-2018-17580: tcpreplay - A heap-based buffer over-read exists in the function fast_edit_packet() in the f...2018

💬Community

3
Bugzilla
CVE-2018-17580 tcpreplay: heap-based buffer over-read in fast_edit_packet() in file send_packets.c [fedora-all]2018-10-01
Bugzilla
CVE-2018-17580 tcpreplay: heap-based buffer over-read in fast_edit_packet() in file send_packets.c [epel-all]2018-10-01
Bugzilla
CVE-2018-17580 tcpreplay: heap-based buffer over-read in fast_edit_packet() in file send_packets.c2018-10-01
CVE-2018-17580 (HIGH CVSS 7.1) | A heap-based buffer over-read exist | cvebase.io