First published: Sat Mar 26 2022(Updated: )
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Broadcom Tcpreplay | =4.4.1 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
Fedoraproject Fedora | =37 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27940
The severity of CVE-2022-27940 is high.
Tcpreplay 4.4.1 is affected by CVE-2022-27940.
CVE-2022-27940 manifests as a heap-based buffer over-read in get_ipv6_next in common/get.c.
Yes, you can refer to the following links for more information on CVE-2022-27940: [Reference 1](https://github.com/appneta/tcpreplay/issues/718), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5B75AFRJUGOYHCFG2ZV2JKSUPA6MSCT5/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ECRCFJ6X3IVB7BT4KS6AHQMSL532YXYD/)