Use After Free Vulnerability in tcpslice by the tcpdump Group
CVE-2021-41043

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
5 January 2022

What is CVE-2021-41043?

The vulnerability identified in tcpslice involves a use after free scenario, which may lead to unpredictable behavior when managing memory in network data manipulation. Triggers detected by AddressSanitizer indicate that improper memory handling can compromise system integrity. While no other confirmed impacts have been documented, the potential for exploitation exists, warranting a review of the affected versions.

Affected Version(s)

tcpslice < 1.5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mohammad Hosein Askari (@C0NSTANTINE110) - https://www.linkedin.com/in/mohammadhoseinaskari
.