Bugzilla – Bug 1218249
VUL-0: CVE-2023-4256: tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c
Last modified: 2023-12-20 09:15:03 UTC
tcprewrite in tcpreplay v4.4.4 and v.4.4.3 has a double free in function tcpedit_dlt_cleanup in plugins/dlt_plugins.c. It can be triggered by sending a crafted file to the tcprewrite binary. It allows a local attacker to cause Denial of Service or possibly have unspecified other impact. https://github.com/appneta/tcpreplay/issues/813 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-4256
Please submit for the following code streams: openSUSE:Backports:SLE-15-SP4:Update tcpreplay v4.4.4 openSUSE:Backports:SLE-15-SP5:Update tcpreplay v4.4.4 openSUSE:Backports:SLE-15-SP6 tcpreplay v4.4.4 openSUSE:Factory tcpreplay v4.4.4