appneta tcpreplay
cpe:2.3:a:appneta:tcpreplay:*:*:*:*:*:*:*
- 4.4.4
A denial-of-service vulnerability has been identified in Tcpreplay version 4.4.4. The issue arises from an infinite loop in the Tcprewrite function within get.c. This loop can be exploited by crafting a malicious pcap input file, causing the program to run indefinitely without termination.
Exploitation of this vulnerability leads to an infinite loop, causing the program to hang and consume resources without completing its task.
The vulnerability can be reproduced by compiling Tcpreplay with Clang and AddressSanitizer enabled, then running the Tcprewrite tool with a specially crafted pcap file that triggers the infinite loop.
Users can update to Tcpreplay version 4.5, where this issue has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.