cbcvebase.

Debian Tcpreplay vulnerabilities

48 known vulnerabilities affecting debian/tcpreplay.

Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2LOW41

Vulnerabilities

Page 2 of 3
CVE-2022-27941P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-27941 [HIGH] CVE-2022-27941: tcpreplay - tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_pro... tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2023-27786P4LOWCVSS 7.5fixed in tcpreplay 4.4.4-1 (forky)2023
CVE-2023-27786 [HIGH] CVE-2023-27786: tcpreplay - An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of ... An issue found in TCPprep v.4.4.3 allows a remote attacker to cause a denial of service via the macinstring function. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.4.4-1) sid: resolved (fixed in 4.4.4-1) trixie: resolved (fixed in 4.4.4-1)
debian
CVE-2022-37049P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-37049 [HIGH] CVE-2022-37049: tcpreplay - The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based... The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2022-37047P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-37047 [HIGH] CVE-2022-37047: tcpreplay - The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-ba... The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2022-37048P4LOWCVSS 7.8fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-37048 [HIGH] CVE-2022-37048: tcpreplay - The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-ba... The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2022-27416P4LOWCVSS 7.8fixed in tcpreplay 4.4.1-1 (bookworm)2022
CVE-2022-27416 [HIGH] CVE-2022-27416: tcpreplay - Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. Tcpreplay v4.4.1 was discovered to contain a double-free via __interceptor_free. Scope: local bookworm: resolved (fixed in 4.4.1-1) bullseye: open forky: resolved (fixed in 4.4.1-1) sid: resolved (fixed in 4.4.1-1) trixie: resolved (fixed in 4.4.1-1)
debian
CVE-2019-8377P4LOWCVSS 7.8fixed in tcpreplay 4.3.1-2 (bookworm)2019
CVE-2019-8377 [HIGH] CVE-2019-8377: tcpreplay - An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred ... An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixe
debian
CVE-2019-8376P4LOWCVSS 7.8fixed in tcpreplay 4.3.1-2 (bookworm)2019
CVE-2019-8376 [HIGH] CVE-2019-8376: tcpreplay - An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred ... An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed i
debian
CVE-2018-20552P4LOWCVSS 7.8fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-20552 [HIGH] CVE-2018-20552: tcpreplay - Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.... Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed in 4.3.1-1) trixie: resolved (fixed in 4.3.1-1)
debian
CVE-2018-20553P4LOWCVSS 7.8fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-20553 [HIGH] CVE-2018-20553: tcpreplay - Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/... Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fixed in 4.3.1-1) sid: resolved (fixed in 4.3.1-1) trixie: resolved (fixed in 4.3.1-1)
debian
CVE-2019-8381P4LOWCVSS 7.8fixed in tcpreplay 4.3.1-2 (bookworm)2019
CVE-2019-8381 [HIGH] CVE-2019-8381: tcpreplay - An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in d... An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 4.3.1-2) bullseye: resol
debian
CVE-2023-43279P4LOWCVSS 6.5fixed in tcpreplay 4.5.1-1 (forky)2023
CVE-2023-43279 [MEDIUM] CVE-2023-43279: tcpreplay - Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 al... Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 4.5.1-1) sid: resolved (fixed in 4.5.1-1) trixie: resolved (fixed in 4.5.1-1)
debian
CVE-2018-17582P4HIGHCVSS 7.1fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-17582 [HIGH] CVE-2018-17582: tcpreplay - Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_pack... Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function unsafely to copy sequences from the source buffer pktdata to the destination (*prev_packet)->pktdata. This will result in a Denial of Service (DoS) and potentially Information Exposure when the application attempts to
debian
CVE-2025-9386P4LOWCVSS 4.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9386 [MEDIUM] CVE-2025-9386: tcpreplay - A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted el... A vulnerability has been found in appneta tcpreplay up to 4.5.1. The impacted element is the function get_l2len_protocol of the file get.c of the component tcprewrite. Such manipulation leads to use after free. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Upgrading to version 4.5.2-beta3 is sufficient to res
debian
CVE-2025-9157P4LOWCVSS 4.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9157 [MEDIUM] CVE-2025-9157: tcpreplay - A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impac... A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. This patc
debian
CVE-2018-17580P4HIGHCVSS 7.1fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-17580 [HIGH] CVE-2018-17580: tcpreplay - A heap-based buffer over-read exists in the function fast_edit_packet() in the f... A heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can lead to Denial of Service (DoS) and potentially Information Exposure when the application attempts to process a crafted pcap file. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: reso
debian
CVE-2025-9649P4LOWCVSS 4.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9649 [MEDIUM] CVE-2025-9649: tcpreplay - A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted ... A security vulnerability has been detected in appneta tcpreplay 4.5.1. Impacted is the function calc_sleep_time of the file send_packets.c. Such manipulation leads to divide by zero. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 4.5.3-beta3 is recommended to address this issue. It is advisable
debian
CVE-2025-9384P4LOWCVSS 4.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9384 [MEDIUM] CVE-2025-9384: tcpreplay - A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the f... A vulnerability was detected in appneta tcpreplay up to 4.5.1. Impacted is the function tcpedit_post_args of the file /src/tcpedit/parse_args.c. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 4.5.2-beta2 is recommended to address this issue. Upgrad
debian
CVE-2025-9385P4LOWCVSS 4.8fixed in tcpreplay 4.5.2-1 (forky)2025
CVE-2025-9385 [MEDIUM] CVE-2025-9385: tcpreplay - A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is ... A flaw has been found in appneta tcpreplay up to 4.5.1. The affected element is the function fix_ipv6_checksums of the file edit_packet.c of the component tcprewrite. This manipulation causes use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version 4.5.2-beta3 is sufficient to fix this issue.
debian
CVE-2020-18976P4LOWCVSS 7.8fixed in tcpreplay 4.3.3-1 (bookworm)2020
CVE-2020-18976 [HIGH] CVE-2020-18976: tcpreplay - Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Servic... Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381. Scope: local bookworm: resolved (fixed in 4.3.3-1) bullseye: resolved (fixed in 4.3.3-1) forky: resolved (fix
debian
Debian Tcpreplay vulnerabilities | cvebase