PatchSiren cyber security CVE debrief
CVE-2017-5202 Redhat CVE debrief
CVE-2017-5202 is a critical memory-corruption issue in tcpdump's ISO CLNS parser. The vulnerable path is clnp_print() in print-isoclns.c, and NVD rates the issue CVSS 3.0 9.8 with network reachability, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
- Vendor
- Redhat
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Anyone running tcpdump before 4.9.0 should treat this as important, especially systems that inspect untrusted network traffic. Administrators of Debian 8/9 and the Red Hat Enterprise Linux variants listed in NVD should also verify whether their packaged tcpdump builds are fixed.
Technical summary
The NVD record identifies a buffer overflow in tcpdump's ISO CLNS parser, specifically print-isoclns.c:clnp_print(), and maps the weakness to CWE-119. The vulnerable range is tcpdump before 4.9.0. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates a remotely reachable issue that does not require privileges or user interaction and can have severe impact if triggered.
Defensive priority
Immediate. This is a critical patching item for any tcpdump deployment that can process untrusted packets.
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or later.
- Prioritize remediation on hosts that capture, relay, or inspect untrusted network traffic.
- Check distribution backports and vendor advisories for the exact fixed package version on Debian and Red Hat systems.
- Confirm whether any tcpdump instances are embedded in appliances, containers, or monitoring stacks that may need separate updates.
- If patching must be deferred, reduce exposure by limiting tcpdump use on untrusted traffic paths until updates are applied.
Evidence notes
The supplied NVD metadata describes a buffer overflow in tcpdump's ISO CLNS parser, identifies tcpdump versions before 4.9.0 as vulnerable, and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD also lists Debian, Red Hat, and Gentoo advisories as references and includes Debian 8/9 plus several Red Hat Enterprise Linux CPE entries. The supplied vendor metadata appears inconsistent with the CVE description because the affected product is tcpdump.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5202 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5202
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5202 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5202
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.