Candidate: CVE-2020-23273 PublicDate: 2021-09-22 00:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23273 https://github.com/appneta/tcpreplay/issues/579 Description: Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_tcpreplay: upstream: https://github.com/appneta/tcpreplay/commit/314ae7d70aa7630dc17dfdb06edacb131fa8fa99 upstream_tcpreplay: released (4.3.3-1) trusty_tcpreplay: ignored (out of standard support) trusty/esm_tcpreplay: DNE (trusty was needed) xenial_tcpreplay: ignored (out of standard support, was needed) bionic_tcpreplay: needed focal_tcpreplay: needed hirsute_tcpreplay: not-affected (4.3.3-2) impish_tcpreplay: not-affected (4.3.3-2) jammy_tcpreplay: not-affected devel_tcpreplay: not-affected