Описание
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| tcpreplay | fixed | 4.3.1-1 | package | |
| tcpreplay | no-dsa | stretch | package | |
| tcpreplay | no-dsa | jessie | package |
Примечания
https://github.com/appneta/tcpreplay/issues/530
https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2
initial set of fixes got additional hardening, see:
https://github.com/appneta/tcpreplay/issues/530#issuecomment-480312372
https://github.com/appneta/tcpreplay/pull/584
Связанные уязвимости
CVSS3: 7.8
ubuntu
около 7 лет назад
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
CVSS3: 7.8
nvd
около 7 лет назад
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
CVSS3: 7.8
github
больше 3 лет назад
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.