CVE-2018-20552: High severity tcpreplay vulnerability
Published Dec 28, 2018
·Updated
Tcpreplay before 4.3.1 has a heap-based buffer over-read in packet2tree in tree.c.
Affected Software
1 affected component
Broadcom Tcpreplay<4.3.1
Remediation
Event History
Dec 28, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-20552?
CVE-2018-20552 is a vulnerability in Tcpreplay before version 4.3.1 that allows for a heap-based buffer over-read in the packet2tree function in tree.c.
2
How severe is CVE-2018-20552?
CVE-2018-20552 has a severity rating of 7.8 (high).
3
Which software versions are affected by CVE-2018-20552?
Versions of Broadcom Tcpreplay up to but excluding 4.3.1 are affected by CVE-2018-20552.
4
How can I fix CVE-2018-20552?
To fix CVE-2018-20552, update your Tcpreplay software to version 4.3.1 or newer.
5
Where can I find more information about CVE-2018-20552?
You can find more information about CVE-2018-20552 at the following references: [link1](https://github.com/appneta/tcpreplay/issues/530), [link2](https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2).