CVE-2016-6160: High severity Broadcom Tcpreplay vulnerability
Published Jul 2, 2016
·Updated
tcprewrite in tcpreplay before 4.1.2 allows remote attackers to cause a denial of service (segmentation fault) via a large frame, a related issue to CVE-2017-14266.
Affected Software
3 affected componentsFixes available
debian/tcpreplay<=3.4.4-2, <=3.4.3-2
3.4.4-33.4.4-2+deb8u1
Broadcom Tcpreplay<=4.1.1
debian/tcpreplay
4.3.3-24.4.3-14.5.1-1
Remediation
Patch Available
Event History
Jan 23, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Data Sourced
via NVD·09:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-6160?
CVE-2016-6160 is considered to have a medium severity due to its potential to cause denial of service through segmentation faults.
2
How do I fix CVE-2016-6160?
To fix CVE-2016-6160, upgrade to tcpreplay version 4.1.2 or later, or any patched version specified by your distribution.
3
Which versions of tcpreplay are affected by CVE-2016-6160?
Versions of tcpreplay up to and including 4.1.1 are affected by CVE-2016-6160.
4
What kind of vulnerability is CVE-2016-6160?
CVE-2016-6160 is a denial of service vulnerability caused by remote attackers sending large frames.
5
Is CVE-2016-6160 specific to any platform?
CVE-2016-6160 primarily affects the Debian-based distributions of tcpreplay.