MGASA-2019-0158
Dashboard / Vulnerabilities / MGASA-2019-0158
MGASA-2019-0158
Summary: Updated tcpreplay packages fixes security vulnerabilities
Details: Updated tcpreplay package fixes security vulnerabilities: An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact (CVE-2019-8376). An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact (CVE-2019-8377). An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact (CVE-2019-8381).
References: https://advisories.mageia.org/MGASA-2019-0158.html, https://bugs.mageia.org/show_bug.cgi?id=24581, https://lists.fedoraproject.org/archives/list/[email protected]/thread/4V3SADKXUSHWTVAPU3WLXBDEQUHRA6ZO/
Affected packages
Package
Name: tcpreplay
Purl: pkg:rpm/mageia/tcpreplay?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
