CVE-2023-4256: Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c
Last updated 28 January 2025
Other sources
tcprewrite in tcpreplay v4.4.4 and v.4.4.3 has a double free in function tcpeditdltcleanup in plugins/dltplugins.c. It can be triggered by sending a crafted file to the tcprewrite binary. It allows a local attacker to cause Denial of Service or possibly have unspecified other impact.
https://github.com/appneta/tcpreplay/issues/813
— Red Hat
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpeditdltcleanup() function within plugins/dltplugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4256?
CVE-2023-4256 is categorized as a potential Denial of Service vulnerability.
How do I fix CVE-2023-4256?
To fix CVE-2023-4256, upgrade to tcpreplay version 4.5.1-1 or higher.
What versions of tcpreplay are affected by CVE-2023-4256?
CVE-2023-4256 affects tcpreplay versions 4.4.3 and 4.4.4.
Can CVE-2023-4256 be triggered remotely?
No, CVE-2023-4256 can only be triggered by a local attacker with a crafted file.
What software is impacted by CVE-2023-4256?
CVE-2023-4256 impacts various packages of tcpreplay across different distributions including Debian and Fedora.