CVE-2022-27942 (https://github.com/appneta/tcpreplay/issues/719): tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. CVE-2022-27941 (https://github.com/appneta/tcpreplay/issues/716): tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. CVE-2022-27940 (https://github.com/appneta/tcpreplay/issues/718): tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. CVE-2022-27939 (https://github.com/appneta/tcpreplay/issues/717): tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. Unfixed upstream.
CVE-2022-28487 (https://github.com/appneta/tcpreplay/pull/720): Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.