CVE-2018-17582
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Tcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy() function unsafely to copy sequences from the source buffer pktdata to the destination (*prev_packet)->pktdata. This will result in a Denial of Service (DoS) and potentially Information Exposure when the application attempts to process a file.
tcpreplay v4.3.0 contiene una sobrelectura de búfer basada en memoria dinámica (heap). La función get_next_packet() en el archivo send_packets.c emplea la función memcpy() de forma no segura para copiar secuencias del búfer de origen pktdata al destino (*prev_packet)->pktdata. Esto resultará en una denegación de servicio (DoS) y una potencial exposición de información cuando la aplicación intenta procesar un archivo.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-28 CVE Reserved
- 2018-09-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/SegfaultMasters/covering360/blob/master/tcpreplay | 2024-08-05 | |
https://github.com/appneta/tcpreplay/issues/484 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Broadcom Search vendor "Broadcom" | Tcpreplay Search vendor "Broadcom" for product "Tcpreplay" | 4.3.0 Search vendor "Broadcom" for product "Tcpreplay" and version "4.3.0" | beta1 |
Affected
| ||||||
Broadcom Search vendor "Broadcom" | Tcpreplay Search vendor "Broadcom" for product "Tcpreplay" | 4.3.0 Search vendor "Broadcom" for product "Tcpreplay" and version "4.3.0" | beta2 |
Affected
|