CVE-2018-18407: Medium severity tcpreplay vulnerability
Published Oct 17, 2018
·Updated
A heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum operation. The issue gets triggered in the function csumreplace4() in incrementalchecksum.h, causing a denial of service.
Affected Software
3 affected components
Broadcom Tcpreplay=4.3.0-beta1
fedoraproject fedora=28
fedoraproject fedora=29
Remediation
Patch Available
Event History
Oct 17, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-18407?
CVE-2018-18407 is a heap-based buffer over-read vulnerability in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1.
2
How does CVE-2018-18407 affect Tcpreplay?
CVE-2018-18407 causes a denial of service in Tcpreplay 4.3.0 beta1 during the incremental checksum operation.
3
What software versions are affected by CVE-2018-18407?
CVE-2018-18407 affects Tcpreplay 4.3.0 beta1, Fedora 28, and Fedora 29.
4
What is the severity of CVE-2018-18407?
CVE-2018-18407 has a severity score of 5.5, which is categorized as medium.
5
How to fix CVE-2018-18407?
It is recommended to upgrade Tcpreplay to a version that is not affected by CVE-2018-18407.