Candidate: CVE-2020-18976 PublicDate: 2021-08-25 16:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-18976 https://github.com/appneta/tcpreplay/issues/556 Description: Buffer Overflow in Tcpreplay v4.3.2 allows attackers to cause a Denial of Service via the 'do_checksum' function in 'checksum.c'. It can be triggered by sending a crafted pcap file to the 'tcpreplay-edit' binary. This issue is different than CVE-2019-8381. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_tcpreplay: upstream: https://github.com/appneta/tcpreplay/pull/591/commits/f3fe91fc65d17687822ed8f376f2e54b97f18291 upstream: https://github.com/appneta/tcpreplay/commit/e1cec7746cd52ab4910289e3b0f72e7c888022d2 upstream_tcpreplay: released (4.3.3-1) trusty_tcpreplay: ignored (out of standard support) trusty/esm_tcpreplay: DNE (trusty was needed) xenial_tcpreplay: ignored (out of standard support, was needed) bionic_tcpreplay: needed focal_tcpreplay: needed hirsute_tcpreplay: not-affected (4.3.3-2) impish_tcpreplay: not-affected (4.3.3-2) jammy_tcpreplay: not-affected devel_tcpreplay: not-affected