CVE-2018-20552,CVE-2018-20553,tcpreplay: no-dsa for Jessie
The heap-based buffer overflows are reproducible with ASAN, without ASAN the tcprep tool segfaults. Since we have marked similar issues as no-dsa in the past and none of our sponsors uses it, I also mark it as no-dsa. In addition to exploit this issue one has to manipulate a pcap file and trick someone into using it.
Loading
Please register or sign in to comment