Vulnerabilities > CVE-2023-4256 - Double Free vulnerability in multiple products
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 | |
Application | 1 | |
OS | 1 |
Common Weakness Enumeration (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2255212
- https://github.com/appneta/tcpreplay/issues/813
- https://lists.fedoraproject.org/archives/list/[email protected]/message/V3GYCHPVJ2VFN3D7FI4IRMDVMILLWBRF/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/TMW5CIODKRHUUH7NTAYIRWGSJ56DTGXM/
- https://lists.fedoraproject.org/archives/list/[email protected]/message/EHUILQV2YJI5TXXXJA5FQ2HJQGFT7NTN/