First published: Fri Dec 28 2018(Updated: )
Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Tcpreplay | <4.3.1 |
https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20553 is a vulnerability in Tcpreplay before version 4.3.1 that allows a heap-based buffer over-read in the get_l2len function in common/get.c.
CVE-2018-20553 has a severity rating of 7.8 (high).
The affected software is Broadcom Tcpreplay version up to but exclusive of 4.3.1.
To fix CVE-2018-20553, update Tcpreplay to version 4.3.1 or later.
You can find more information about CVE-2018-20553 in the following references: [GitHub Issue](https://github.com/appneta/tcpreplay/issues/530), [GitHub Pull Request](https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2).