CVE-2019-8377: Broadcom Tcpreplay

High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.

An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Affected products

  • Broadcom Tcpreplay: version 4.3.1 only
  • Fedoraproject Fedora: version 28 only; version 29 only; version 30 only; version 31 only; version 32 only

Published 2019-02-17. Last modified 2026-06-17.