Candidate: CVE-2020-12740 PublicDate: 2020-05-08 18:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12740 https://github.com/appneta/tcpreplay/issues/576 Description: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H [9.1 CRITICAL] Patches_tcpreplay: upstream: https://github.com/appneta/tcpreplay/pull/587/commits/71ea80ba8756fff1d9242a70484f64906ab8e6ae upstream: https://github.com/appneta/tcpreplay/pull/587/commits/5113429140250e9640c3eca1be7745ff8380d363 upstream_tcpreplay: released (4.3.3) precise/esm_tcpreplay: DNE trusty_tcpreplay: ignored (out of standard support) trusty/esm_tcpreplay: DNE (trusty was not-affected [code not present]) xenial_tcpreplay: ignored (end of standard support, was not-affected [code not present]) bionic_tcpreplay: needed eoan_tcpreplay: ignored (reached end-of-life) focal_tcpreplay: needed groovy_tcpreplay: not-affected (4.3.3-2) hirsute_tcpreplay: not-affected (4.3.3-2) impish_tcpreplay: not-affected (4.3.3-2) jammy_tcpreplay: not-affected (4.3.3-2) devel_tcpreplay: not-affected (4.3.3-2)