REDHAT-BUG-2255212: Double Free
tcprewrite in tcpreplay v4.4.4 and v.4.4.3 has a double free in function tcpeditdltcleanup in plugins/dltplugins.c. It can be triggered by sending a crafted file to the tcprewrite binary. It allows a local attacker to cause Denial of Service or possibly have unspecified other impact.
https://github.com/appneta/tcpreplay/issues/813
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2255212?
The severity of REDHAT-BUG-2255212 is considered to be high due to the potential for Denial of Service and unspecified impacts.
How do I fix REDHAT-BUG-2255212?
To fix REDHAT-BUG-2255212, upgrade to tcpreplay version 4.4.5 or later where the vulnerability has been addressed.
What causes the vulnerability REDHAT-BUG-2255212?
The vulnerability REDHAT-BUG-2255212 is caused by a double free in the tcprewrite utility's tcpedit_dlt_cleanup function.
Who is affected by REDHAT-BUG-2255212?
Users of Appneta's tcpreplay versions 4.4.4 and 4.4.3 are affected by REDHAT-BUG-2255212.
Can REDHAT-BUG-2255212 be exploited remotely?
No, REDHAT-BUG-2255212 requires local access to exploit the vulnerability.