NULL pointer dereference in Tcpreplay - CVE-2023-43279
Published: March 20, 2024
Vulnerability identifier: #VU87649
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-43279
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the mask_cidr6 component in cidr.c. A remote attacker can trigger denial of service conditions via crafted tcprewrite command.
Affected software
Tcpreplay
Fedora
Ubuntu
tcpreplay (Ubuntu package)
tcpreplay
Fedora
Ubuntu
tcpreplay (Ubuntu package)
tcpreplay
How to mitigate CVE-2023-43279
Install update from vendor's website.
tcpreplay (Ubuntu package) - update to Ubuntu Pro
tcpreplay - addressed in versions 4.4.4-5.el7, 4.4.4-5.el8, 4.4.4-5.el9, 4.4.4-5.fc38, 4.4.4-5.fc39, 4.4.4-5.fc40
tcpreplay - addressed in versions 4.4.4-5.el7, 4.4.4-5.el8, 4.4.4-5.el9, 4.4.4-5.fc38, 4.4.4-5.fc39, 4.4.4-5.fc40