Description
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: None
Availability: High
Affected Packages2 packages
Also affects: Fedora 31, 32
🔴Vulnerability Details
3GHSAGHSA-95wm-mm55-cxhx: tcprewrite in Tcpreplay through 4↗2022-05-24 ▶ OSVCVE-2020-12740: tcprewrite in Tcpreplay through 4↗2020-05-08 ▶ CVEListCVE-2020-12740: tcprewrite in Tcpreplay through 4↗2020-05-08 ▶ 📋Vendor Advisories
2UbuntuTcpreplay vulnerabilities↗2022-10-04 ▶ DebianCVE-2020-12740: tcpreplay - tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a...↗2020 ▶ 💬Community
2BugzillaCVE-2020-12740 tcpreplay: Heap-based buffer over-read in function get_ipv6_next() at common/get.c↗2020-05-13 ▶ BugzillaCVE-2020-12740 tcpreplay: Heap-based buffer over-read in function get_ipv6_next() at common/get.c [fedora-all]↗2020-05-13 ▶