CVE-2022-27941: High severity tcpreplay vulnerability
Published Mar 26, 2022
·Updated
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in getl2lenprotocol in common/get.c.
Affected Software
4 affected components
Broadcom Tcpreplay=4.4.1
fedoraproject fedora=35
fedoraproject fedora=36
fedoraproject fedora=37
Event History
Mar 26, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-27941.
2
What is the severity of CVE-2022-27941?
The severity of CVE-2022-27941 is high with a CVSS score of 7.8.
3
What software versions are affected by CVE-2022-27941?
Tcpreplay 4.4.1 and Fedora 35, 36, and 37 are affected by CVE-2022-27941.
4
What is the CWE ID associated with CVE-2022-27941?
The CWE ID associated with CVE-2022-27941 is CWE-125.
5
How can I fix the vulnerability CVE-2022-27941?
To fix the vulnerability CVE-2022-27941, update Tcpreplay to a version that includes the patch provided by the vendor.