CVE-2022-27940: High severity tcpreplay vulnerability
Published Mar 26, 2022
·Updated
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in getipv6next in common/get.c.
Affected Software
4 affected components
Broadcom Tcpreplay=4.4.1
fedoraproject fedora=35
fedoraproject fedora=36
fedoraproject fedora=37
Event History
Mar 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
CVE-2022-27940
2
What is the severity of CVE-2022-27940?
The severity of CVE-2022-27940 is high.
3
What software versions are affected by CVE-2022-27940?
Tcpreplay 4.4.1 is affected by CVE-2022-27940.
4
How does CVE-2022-27940 manifest?
CVE-2022-27940 manifests as a heap-based buffer over-read in get_ipv6_next in common/get.c.
5
Are there any references for CVE-2022-27940?
Yes, you can refer to the following links for more information on CVE-2022-27940: [Reference 1](https://github.com/appneta/tcpreplay/issues/718), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5B75AFRJUGOYHCFG2ZV2JKSUPA6MSCT5/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRCFJ6X3IVB7BT4KS6AHQMSL532YXYD/)