CVE-2018-13112: High severity tcpreplay vulnerability
Published Jul 3, 2018
·Updated
getl2len in common/get.c in Tcpreplay 4.3.0 beta1 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via crafted packets, as demonstrated by tcpprep.
Affected Software
1 affected component
Broadcom Tcpreplay=4.3.0-beta1
Event History
Jul 3, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-13112?
CVE-2018-13112 is a vulnerability in Tcpreplay 4.3.0 beta1 that allows remote attackers to cause a denial of service.
2
How does CVE-2018-13112 work?
CVE-2018-13112 works by exploiting a heap-based buffer over-read and causing an application crash when crafted packets are sent.
3
Which version of Tcpreplay is affected by CVE-2018-13112?
Tcpreplay 4.3.0 beta1 is affected by CVE-2018-13112.
4
What is the severity of CVE-2018-13112?
CVE-2018-13112 has a severity rating of 7.5 (high).
5
Is there a fix available for CVE-2018-13112?
A fix for CVE-2018-13112 may be available through updates or patches provided by Broadcom Tcpreplay.