PT-2019-18996 · Astron Security+1 · Tcpreplay+1
Mastersop
·
Published
2019-02-17
·
Updated
2024-06-15
·
CVE-2019-8377
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Tcpreplay version 4.3.1
Description
An issue was discovered in the function
get ipv6 l4proto() located at get.c, which can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. This can cause a NULL pointer dereference, allowing an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.Recommendations
For Tcpreplay version 4.3.1, consider avoiding the use of crafted pcap files with the
tcpreplay-edit binary until a patch is available. As a temporary workaround, restrict access to the get ipv6 l4proto() function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Tcpreplay