PT-2019-18996 · Astron Security+1 · Tcpreplay+1
Mastersop
·
Publicado
2019-02-17
·
Atualizado
2024-06-15
·
CVE-2019-8377
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tcpreplay version 4.3.1
Description
An issue was discovered in the function
get ipv6 l4proto() located at get.c, which can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. This can cause a NULL pointer dereference, allowing an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Recommendations
For Tcpreplay version 4.3.1, consider avoiding the use of crafted pcap files with the
tcpreplay-edit binary until a patch is available. As a temporary workaround, restrict access to the get ipv6 l4proto() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
NULL Pointer Dereference
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Tcpreplay