Candidate: CVE-2018-20553 PublicDate: 2018-12-28 16:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20553 https://github.com/appneta/tcpreplay/issues/530 https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2 Description: Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c. Ubuntu-Description: Notes: ccdm94> version 4.3.2 includes the fix applied by the original patch, ccdm94> however, additional fixes have been released since, and 4.3.2 ccdm94> does not include those. Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=917574 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_tcpreplay: upstream: https://github.com/appneta/tcpreplay/pull/584/commits/4f51c34c353759701057178f45dc7ba37e014994 upstream: https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2 upstream_tcpreplay: released (4.3.3) precise/esm_tcpreplay: DNE trusty_tcpreplay: ignored (reached end-of-life) trusty/esm_tcpreplay: DNE (trusty was needed) xenial_tcpreplay: ignored (end of standard support, was needed) bionic_tcpreplay: needed cosmic_tcpreplay: ignored (reached end-of-life) disco_tcpreplay: not-affected (4.3.1-2) eoan_tcpreplay: ignored (reached end-of-life) focal_tcpreplay: needed groovy_tcpreplay: ignored (reached end-of-life) hirsute_tcpreplay: not-affected (4.3.3-2) impish_tcpreplay: not-affected (4.3.3-2) jammy_tcpreplay: not-affected devel_tcpreplay: not-affected