CVE-2020-24265: Buffer Overflow
Published Oct 19, 2020
·Updated
An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.
Affected Software
4 affected components
Broadcom Tcpreplay=4.3.3
fedoraproject fedora=31
fedoraproject fedora=32
fedoraproject fedora=33
Remediation
Patch Available
Event History
Oct 19, 2020
CVE Published
via MITRE·02:58 PM
Data Sourced
via MITRE·02:58 PM
Description
Frequently Asked Questions
1
What is CVE-2020-24265?
CVE-2020-24265 is a heap buffer overflow vulnerability in tcpreplay tcpprep v4.3.3.
2
What is the severity of CVE-2020-24265?
The severity of CVE-2020-24265 is high (7.5).
3
Which software versions are affected by CVE-2020-24265?
Versions 4.3.3 of Broadcom Tcpreplay and Fedora 31, 32, and 33 are affected by CVE-2020-24265.
4
How does CVE-2020-24265 impact the affected software?
CVE-2020-24265 can cause a denial of service by crashing Tcpreplay.
5
Is there a fix or patch available for CVE-2020-24265?
There is currently no fix or patch available for CVE-2020-24265. It is recommended to update to a version that is not affected.