iptraf-ng 1.2.1 has a stack-based buffer overflow. In src/ifaces.c, the strcpy function consistently fails to control the size, and it is consequently possible to overflow memory on the stack.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-iptraf-ng | Jul 4, 2025 | Dec 16, 2024 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-iptraf-ngamazon-linux-ami-2-upgrade-iptraf-ng-debuginfo | Apr 2, 2025 | Dec 16, 2024 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Dec 16, 2024 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-iptraf-ng | Mar 18, 2025 | Dec 16, 2024 | |
| Huawei Euleros 2_0_sp11 | huawei-euleros-2_0_sp11-upgrade-iptraf-ng | Feb 11, 2025 | Dec 16, 2024 | |
| Huawei Euleros 2_0_sp12 | huawei-euleros-2_0_sp12-upgrade-iptraf-ng | Feb 11, 2025 | Dec 16, 2024 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-iptraf-ng | Mar 18, 2025 | Dec 16, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-iptraf-ng | May 26, 2025 | Dec 16, 2024 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-iptraf-ngredhat-upgrade-iptraf-ng-debuginforedhat-upgrade-iptraf-ng-debugsource | May 14, 2025 | Dec 16, 2024 | |
| Rocky_linux | rocky-upgrade-iptraf-ngrocky-upgrade-iptraf-ng-debuginforocky-upgrade-iptraf-ng-debugsource | Oct 6, 2025 | Oct 4, 2025 | |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Dec 16, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Feb 9, 2026 | Dec 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub