Tcpreplay before 4.3.1 has a heap-based buffer over-read in get_l2len in common/get.c.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-20553.json"