{"id":"CVE-2018-20553","details":"Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.","modified":"2026-04-11T21:31:27.396352Z","published":"2018-12-28T16:29:05.160Z","references":[{"type":"FIX","url":"https://github.com/appneta/tcpreplay/pull/532/commits/6b830a1640ca20528032c89a4fdd8291a4d2d8b2"},{"type":"EVIDENCE","url":"https://github.com/appneta/tcpreplay/issues/530"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/appneta/tcpreplay","events":[{"introduced":"0"},{"fixed":"2595c903b61d9e50b22cbfcc6899f8f11a17bbff"}],"database_specific":{"cpe":"cpe:2.3:a:broadcom:tcpreplay:*:*:*:*:*:*:*:*","source":"CPE_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"4.3.1"}]}}],"versions":["v3.4.2","v3.4.3","v3.4.4","v4.0.0","v4.0.0beta1","v4.0.0beta2","v4.0.1","v4.0.2","v4.0.3","v4.0.4","v4.0.5","v4.0.5beta1","v4.0.5beta2","v4.0.5beta3","v4.1.0","v4.1.0beta1","v4.1.0beta2","v4.1.1","v4.1.1-beta2","v4.1.1-beta3","v4.1.2","v4.2.6"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-20553.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}