Out-of-Bounds Affecting tcpreplay package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.01% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-TCPREPLAY-12029340
  • published21 Aug 2025
  • disclosed19 Aug 2025

Introduced: 19 Aug 2025

NewCVE-2025-9157  (opens in a new tab)
CWE-119  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

There is no fixed version for Debian:unstable tcpreplay.

NVD Description

Note: Versions mentioned in the description apply only to the upstream tcpreplay package and not the tcpreplay package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A vulnerability was determined in appneta tcpreplay up to 4.5.2-beta2. The impacted element is the function untrunc_packet of the file src/tcpedit/edit_packet.c of the component tcprewrite. Executing manipulation can lead to use after free. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. This patch is called 73008f261f1cdf7a1087dc8759115242696d35da. Applying a patch is advised to resolve this issue.

CVSS Base Scores

version 3.1