CVE-2018-20553 (NVD)

2018-12-28

Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.

Products Tcpreplay
Type Out-of-bounds Read (CWE-125)
First patch - None (likely due to unavailable code)
Patches https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2
Links https://github.com/appneta/tcpreplay/issues/530