CVE-2020-12740Out-of-bounds Read in Tcpreplay

CWE-125Out-of-bounds Read8 documents7 sources
Severity
9.1CRITICALNVD
EPSS
0.5%
top 33.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateOct 4

Description

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

Debianbroadcom/tcpreplay< 4.3.3-1+3

Also affects: Fedora 31, 32

🔴Vulnerability Details

3
GHSA
GHSA-95wm-mm55-cxhx: tcprewrite in Tcpreplay through 42022-05-24
OSV
CVE-2020-12740: tcprewrite in Tcpreplay through 42020-05-08
CVEList
CVE-2020-12740: tcprewrite in Tcpreplay through 42020-05-08

📋Vendor Advisories

2
Ubuntu
Tcpreplay vulnerabilities2022-10-04
Debian
CVE-2020-12740: tcpreplay - tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a...2020

💬Community

2
Bugzilla
CVE-2020-12740 tcpreplay: Heap-based buffer over-read in function get_ipv6_next() at common/get.c2020-05-13
Bugzilla
CVE-2020-12740 tcpreplay: Heap-based buffer over-read in function get_ipv6_next() at common/get.c [fedora-all]2020-05-13
CVE-2020-12740 — Out-of-bounds Read in Tcpreplay | cvebase