cbcvebase.

Debian Tcpreplay vulnerabilities

48 known vulnerabilities affecting debian/tcpreplay.

Total CVEs
48
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM2LOW41

Vulnerabilities

Page 3 of 3
CVE-2018-17974P4MEDIUMCVSS 5.5fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-17974 [MEDIUM] CVE-2018-17974: tcpreplay - An issue was discovered in Tcpreplay 4.3.0 beta1. A heap-based buffer over-read ... An issue was discovered in Tcpreplay 4.3.0 beta1. A heap-based buffer over-read was triggered in the function dlt_en10mb_encode() of the file plugins/dlt_en10mb/en10mb.c, due to inappropriate values in the function memmove(). The length (pktlen + ctx -> l2len) can be larger than source value (packet + ctx->l2len) because the function fails to ensure the length o
debian
CVE-2020-23273P4LOWCVSS 5.5fixed in tcpreplay 4.3.3-1 (bookworm)2020
CVE-2020-23273 [MEDIUM] CVE-2020-23273: tcpreplay - Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcprep... Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap. Scope: local bookworm: resolved (fixed in 4.3.3-1) bullseye: resolved (fixed in 4.3.3-1) forky: resolved (fixed in 4.3.3-1) sid: resolved (fixed in 4.3.3-1) trixie: resolved (fixed in 4.3.3-1)
debian
CVE-2023-4256P4LOWCVSS 5.5fixed in tcpreplay 4.5.1-1 (forky)2023
CVE-2023-4256 [MEDIUM] CVE-2023-4256: tcpreplay - Within tcpreplay's tcprewrite, a double free vulnerability has been identified i... Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack. Scope: local bookworm: open bullsey
debian
CVE-2018-18407P4MEDIUMCVSS 5.5fixed in tcpreplay 4.3.1-1 (bookworm)2018
CVE-2018-18407 [MEDIUM] CVE-2018-18407: tcpreplay - A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcp... A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csum_replace4() in incremental_checksum.h, causing a denial of service. Scope: local bookworm: resolved (fixed in 4.3.1-1) bullseye: resolved (fixed in 4.3.1-1) forky: resolved (fi
debian
CVE-2021-45386P4LOWCVSS 5.5fixed in tcpreplay 4.4.0-1 (bookworm)2021
CVE-2021-45386 [MEDIUM] CVE-2021-45386: tcpreplay - tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv6() at tree.c Scope: local bookworm: resolved (fixed in 4.4.0-1) bullseye: open forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2021-45387P4LOWCVSS 5.5fixed in tcpreplay 4.4.0-1 (bookworm)2021
CVE-2021-45387 [MEDIUM] CVE-2021-45387: tcpreplay - tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. tcpreplay 4.3.4 has a Reachable Assertion in add_tree_ipv4() at tree.c. Scope: local bookworm: resolved (fixed in 4.4.0-1) bullseye: open forky: resolved (fixed in 4.4.0-1) sid: resolved (fixed in 4.4.0-1) trixie: resolved (fixed in 4.4.0-1)
debian
CVE-2022-27939P4LOWCVSS 5.5fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-27939 [MEDIUM] CVE-2022-27939: tcpreplay - tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in comm... tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
CVE-2022-25484P4LOWCVSS 5.5fixed in tcpreplay 4.4.2-1 (bookworm)2022
CVE-2022-25484 [MEDIUM] CVE-2022-25484: tcpreplay - tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at... tcpprep v4.4.1 has a reachable assertion (assert(l2len > 0)) in packet2tree() at tree.c in tcpprep v4.4.1. Scope: local bookworm: resolved (fixed in 4.4.2-1) bullseye: open forky: resolved (fixed in 4.4.2-1) sid: resolved (fixed in 4.4.2-1) trixie: resolved (fixed in 4.4.2-1)
debian
Debian Tcpreplay vulnerabilities | cvebase