ArchLinux: 202007-3: tcpreplay: information disclosure
Summary
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
Resolution
Upgrade to 4.3.3-1.
# pacman -Syu "tcpreplay>=4.3.3-1"
The problem has been fixed upstream in version 4.3.3.
References
https://github.com/appneta/tcpreplay/issues/576 https://security.archlinux.org/CVE-2020-12740
Workaround
None.