PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-5202 Redhat CVE debrief

CVE-2017-5202 is a critical memory-corruption issue in tcpdump's ISO CLNS parser. The vulnerable path is clnp_print() in print-isoclns.c, and NVD rates the issue CVSS 3.0 9.8 with network reachability, no privileges, no user interaction, and high impact to confidentiality, integrity, and availability.

Vendor
Redhat
Product
Unknown
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-28
Original CVE updated
2026-05-13
Advisory published
2017-01-28
Advisory updated
2026-05-13

Who should care

Anyone running tcpdump before 4.9.0 should treat this as important, especially systems that inspect untrusted network traffic. Administrators of Debian 8/9 and the Red Hat Enterprise Linux variants listed in NVD should also verify whether their packaged tcpdump builds are fixed.

Technical summary

The NVD record identifies a buffer overflow in tcpdump's ISO CLNS parser, specifically print-isoclns.c:clnp_print(), and maps the weakness to CWE-119. The vulnerable range is tcpdump before 4.9.0. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H indicates a remotely reachable issue that does not require privileges or user interaction and can have severe impact if triggered.

Defensive priority

Immediate. This is a critical patching item for any tcpdump deployment that can process untrusted packets.

Recommended defensive actions

  • Upgrade tcpdump to 4.9.0 or later.
  • Prioritize remediation on hosts that capture, relay, or inspect untrusted network traffic.
  • Check distribution backports and vendor advisories for the exact fixed package version on Debian and Red Hat systems.
  • Confirm whether any tcpdump instances are embedded in appliances, containers, or monitoring stacks that may need separate updates.
  • If patching must be deferred, reduce exposure by limiting tcpdump use on untrusted traffic paths until updates are applied.

Evidence notes

The supplied NVD metadata describes a buffer overflow in tcpdump's ISO CLNS parser, identifies tcpdump versions before 4.9.0 as vulnerable, and assigns CVSS 3.0 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. NVD also lists Debian, Red Hat, and Gentoo advisories as references and includes Debian 8/9 plus several Red Hat Enterprise Linux CPE entries. The supplied vendor metadata appears inconsistent with the CVE description because the affected product is tcpdump.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-5202 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-5202

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-5202 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5202

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.