PT-2022-23768 · Tcpreplay+2 · Tcpreplay+2

Chluo1997

·

Published

2022-08-18

·

Updated

2022-11-30

·

CVE-2022-37047

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tcpreplay version 4.4.1
Description A heap-based buffer overflow was discovered in the tcprewrite component of Tcpreplay, specifically in the get ipv6 next function at common/get.c:713.
Recommendations For Tcpreplay version 4.4.1, consider applying a patch or fix to address the heap-based buffer overflow issue in the tcprewrite component. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2022-3223
ALT-PU-2022-3236
ALT-PU-2022-3237
ALT-PU-2022-3245
CVE-2022-37047
MGASA-2022-0345

Affected Products

Alt Linux
Debian
Tcpreplay