Stack-based buffer overflow in Tcpreplay - #VU139400
Published: July 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to stack-based buffer overflow in the tcpprep services file parser in parse_services() when parsing an attacker-supplied services file passed through the --services option. A remote attacker can trick the victim into opening a crafted file to execute arbitrary code.
User interaction is required to run tcpprep with the attacker-supplied services file.