CVE-2023-43279: Null Pointer Dereference
Published Mar 12, 2024
·Updated
Last updated 28 January 2025
Other sources
Null Pointer Dereference in maskcidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
— MITRE
Affected Software
6 affected components
debian/tcpreplay<=4.3.3-2, <=4.4.3-1, <=4.5.1-1
Broadcom Tcpreplay=4.4.4
fedoraproject fedora=38
fedoraproject fedora=39
fedoraproject fedora=40
Tcpreplay Tcpreplay
Event History
Mar 12, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 PM
Affected Software
Jan 28, 2025
Data Sourced
via Ubuntu·05:56 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-43279?
CVE-2023-43279 has a severity rating that indicates it can lead to application crashes due to a null pointer dereference.
2
How do I fix CVE-2023-43279?
To fix CVE-2023-43279, ensure that you update to the latest version of Tcpreplay that resolves this vulnerability.
3
What versions of Tcpreplay are affected by CVE-2023-43279?
CVE-2023-43279 affects Tcpreplay versions up to 4.4.3-1 and 4.5.1-1 in specific package distributions.
4
What component is vulnerable in CVE-2023-43279?
CVE-2023-43279 is a vulnerability in the mask_cidr6 component found in cidr.c of Tcpreplay.
5
Can CVE-2023-43279 be exploited remotely?
Yes, CVE-2023-43279 can potentially be exploited by attackers using a crafted tcprewrite command.