PT-2023-28428 · Grafana+3 · Grafana+3

Iskindar

·

Published

2023-12-21

·

Updated

2025-11-27

·

CVE-2023-4256

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions tcpreplay versions (affected versions not specified) Grafana versions prior to 10.1.4
Description A double free vulnerability has been identified in the tcpedit dlt cleanup() function within plugins/dlt plugins.c of tcpreplay's tcprewrite. This issue can be exploited by supplying a specifically crafted file to the tcprewrite binary, enabling a local attacker to initiate a Denial of Service (DoS) attack. Additionally, a directory traversal vulnerability in Grafana can lead to information disclosure.
Recommendations For tcpreplay, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Grafana versions prior to 10.1.4, update to version 10.1.4 or later to resolve the directory traversal vulnerability.

Exploit

DoS

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-4256
MGASA-2024-0098
OPENSUSE-SU-2025:20119-1
USN-7231-1

Affected Products

Debian
Grafana
Linuxmint
Ubuntu