An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-tcpreplay | Aug 22, 2024 | Feb 17, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Feb 17, 2019 | |
| Debian | debian-upgrade-tcpreplay | Jul 30, 2024 | Feb 17, 2019 | |
| Freebsd | freebsd-upgrade-package-tcpreplay | Jun 12, 2020 | Jun 11, 2020 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Feb 17, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub