Double Free in Tcpreplay - CVE-2023-4256
Published: March 20, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the tcpedit_dlt_cleanup() function in plugins/dlt_plugins.c. A remote attacker can pass specially crafted data to the application, trigger a double free error and perform a denial of service (DoS) attack.
Affected software
Fedora
Ubuntu
tcpreplay (Ubuntu package)
tcpreplay
How to mitigate CVE-2023-4256
tcpreplay - addressed in versions 4.4.4-5.el7, 4.4.4-5.el8, 4.4.4-5.el9, 4.4.4-5.fc38, 4.4.4-5.fc39, 4.4.4-5.fc40