cbcvebase.

Debian Tcpreplay vulnerabilities

48 known vulnerabilities affecting debian/tcpreplay.

Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2LOW41

Vulnerabilities

Page 1 of 3
CVE-2017-14266P3HIGHCVSS 7.5PoCfixed in tcpreplay 3.4.4-3 (bookworm)2017
CVE-2017-14266 [HIGH] CVE-2017-14266: tcpreplay - tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability tri... tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160. Scope: local bookworm: resolved (fixed in 3.4.4-3) bullseye: resolved (fixed in 3.4.4-3) forky: resolved (fixed in 3.4.4-3) sid: resolved (fixed in 3.4.4-3) trixie: resolved (fixed in 3.4.4-3)
debian
CVE-2022-28487P3LOWCVSS 7.5fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-28487 [HIGH] CVE-2022-28487: tcpreplay - Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() f... Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2020-12740P3LOWCVSS 9.1fixed in tcpreplay 4.3.3-1 (bookworm)2020
CVE-2020-12740 [CRITICAL] CVE-2020-12740: tcpreplay - tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a... tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c. Scope: local bookworm: resolved (fixed in 4.3.3-1) bullseye: resolved (fixed in 4.3.3-1) forky: resolved (fixed in 4.3.3-1) sid: resolved (fixed in 4.3.3-1) trixie: resolved (fixed in 4.
debian
CVE-2025-51006P3LOWCVSS 7.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-51006 [HIGH] CVE-2025-51006: tcpreplay - Within tcpreplay's tcprewrite, a double free vulnerability has been identified i... Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the dlt_linuxsll2_cleanup() function in plugins/dlt_linuxsll2/linuxsll2.c. This vulnerability is triggered when tcpedit_dlt_cleanup() indirectly invokes the cleanup routine multiple times on the same memory region. By supplying a specifically crafted pcap file to the tcprewrite binar
debian
CVE-2024-22654P3LOWCVSS 7.5fixed in tcpreplay 4.5.1-1 (forky)2024
CVE-2024-22654 [HIGH] CVE-2024-22654: tcpreplay - tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite f... tcpreplay v4.4.4 was discovered to contain an infinite loop via the tcprewrite function at get.c. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.5.1-1) sid: resolved (fixed in 4.5.1-1) trixie: resolved (fixed in 4.5.1-1)
debian
CVE-2020-24266P3LOWCVSS 7.5fixed in tcpreplay 4.3.4-1 (bookworm)2020
CVE-2020-24266 [HIGH] CVE-2020-24266: tcpreplay - An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer over... An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service. Scope: local bookworm: resolved (fixed in 4.3.4-1) bullseye: open forky: resolved (fixed in 4.3.4-1) sid: resolved (fixed in 4.3.4-1) trixie: resolved (fixed in 4.3.4-1)
debian
CVE-2020-24265P3LOWCVSS 7.5fixed in tcpreplay 4.3.4-1 (bookworm)2020
CVE-2020-24265 [HIGH] CVE-2020-24265: tcpreplay - An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer over... An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service. Scope: local bookworm: resolved (fixed in 4.3.4-1) bullseye: open forky: resolved (fixed in 4.3.4-1) sid: resolved (fixed in 4.3.4-1) trixie: resolved (fixed in 4.3.4-1)
debian
CVE-2023-27784P3LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27784 [HIGH] CVE-2023-27784: tcpreplay - An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial o... An issue found in TCPReplay v.4.4.3 allows a remote attacker to cause a denial of service via the read_hexstring function at the utils.c:309 endpoint. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2023-27788P3LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27788 [HIGH] CVE-2023-27788: tcpreplay - An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial ... An issue found in TCPrewrite v.4.4.3 allows a remote attacker to cause a denial of service via the ports2PORT function at the portmap.c:69 endpoint. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2018-18408P4CRITICALCVSS 9.8fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-18408 [CRITICAL] CVE-2018-18408: tcpreplay - A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1... A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed
debian
CVE-2022-27418P4LOWCVSS 7.8fixed in tcpreplay 4.4.1-1 (bookworm)2022
CVE-2022-27418 [HIGH] CVE-2022-27418: tcpreplay - Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedi... Tcpreplay v4.4.1 has a heap-based buffer overflow in do_checksum_math at /tcpedit/checksum.c. Scope: local bookworm: resolved (fixed in 4.4.1-1) bullseye: open forky: resolved (fixed in 4.4.1-1) sid: resolved (fixed in 4.4.1-1) trixie: resolved (fixed in 4.4.1-1)
debian
CVE-2023-27783P4LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27783 [HIGH] CVE-2023-27783: tcpreplay - An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause... An issue found in TCPreplay tcprewrite v.4.4.3 allows a remote attacker to cause a denial of service via the tcpedit_dlt_cleanup function at plugins/dlt_plugins.c. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2023-27787P4LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27787 [HIGH] CVE-2023-27787: tcpreplay - An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of ... An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse_list function at the list.c:81 endpoint. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2023-27789P4LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27789 [HIGH] CVE-2023-27789: tcpreplay - An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of ... An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the cidr2cidr function at the cidr.c:178 endpoint. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2023-27785P4LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27785 [HIGH] CVE-2023-27785: tcpreplay - An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a ... An issue found in TCPreplay TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the parse endpoints function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2025-9019P3LOWCVSS 2.3fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9019 [LOW] CVE-2025-9019: tcpreplay - A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects th... A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c of the component tcpprep. The manipulation leads to heap-based buffer overflow. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public
debian
CVE-2018-13112P4LOWCVSS 7.5fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-13112 [HIGH] CVE-2018-13112: tcpreplay - get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to ca... get_l2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed in 4.3.1-1) trix
debian
CVE-2016-6160P4HIGHCVSS 7.5fixed in tcpreplay 3.4.4-3 (bookworm)2016
CVE-2016-6160 [HIGH] CVE-2016-6160: tcpreplay - tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial o... tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to CVE-2017-14266. Scope: local bookworm: resolved (fixed in 3.4.4-3) bullseye: resolved (fixed in 3.4.4-3) forky: resolved (fixed in 3.4.4-3) sid: resolved (fixed in 3.4.4-3) trixie: resolved (fixed in 3.4.4-3)
debian
CVE-2022-27942P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-27942 [HIGH] CVE-2022-27942: tcpreplay - tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in co... tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2022-27940P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-27940 [HIGH] CVE-2022-27940: tcpreplay - tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next... tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
Debian Tcpreplay vulnerabilities | cvebase