Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-12740

Опубликовано: 08 мая 2020
Источник: debian

Описание

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tcpreplayfixed4.3.3-1package
tcpreplaynot-affectedjessiepackage

Примечания

  • https://github.com/appneta/tcpreplay/issues/576

  • https://github.com/appneta/tcpreplay/pull/590

  • Fixed with: https://github.com/appneta/tcpreplay/issues/578

  • --fuzz-seed in PoC not present until version 4.2.0

  • Crash in CLI tool, no security impact

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 5 лет назад

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

CVSS3: 9.1
nvd
больше 5 лет назад

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.

CVSS3: 9.1
github
больше 3 лет назад

tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.