Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-4256


Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.


Published

2023-12-21T16:15:10.400

Last Modified

2024-11-21T08:34:44.407

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-415
  • Type: Primary
    CWE-415

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application broadcom tcpreplay 4.4.3 Yes
Application broadcom tcpreplay 4.4.4 Yes
Application fedoraproject extra_packages_for_enterprise_linux 8.0 Yes
Operating System fedoraproject fedora 39 Yes

References