PatchSiren cyber security CVE debrief
CVE-2017-5482 Tcpdump CVE debrief
CVE-2017-5482 is a critical memory-corruption issue in tcpdump's Q.933 parser. The affected code path is print-fr.c:q933_print(), and the CVE description says this is a different vulnerability than CVE-2016-8575. NVD maps the issue to tcpdump versions up to 4.8.1, so any environment still running older builds should treat this as a high-priority update.
- Vendor
- Tcpdump
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-28
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-28
- Advisory updated
- 2026-05-13
Who should care
Security teams, Linux distro maintainers, and operators who use tcpdump to inspect untrusted packet captures or traffic, especially on systems running tcpdump 4.8.1 or earlier.
Technical summary
NVD describes a buffer overflow in print-fr.c:q933_print() in tcpdump's Q.933 parser, classified as CWE-119. The CVSS v3.0 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8), indicating a critical issue with no privileges or user interaction required once the vulnerable parser is reached. The CVE description explicitly notes this is distinct from CVE-2016-8575.
Defensive priority
Critical
Recommended defensive actions
- Upgrade tcpdump to 4.9.0 or later, or install vendor backports that include the fix.
- Inventory hosts and appliances that ship tcpdump, including distro packages, and verify versions are not 4.8.1 or earlier.
- Prefer trusted capture sources and minimize exposure of tcpdump to untrusted or attacker-controlled packet data.
- Track vendor advisories and package errata linked in the CVE record for distribution-specific remediation status.
Evidence notes
Primary evidence comes from the NVD CVE record, which identifies a buffer overflow in q933_print(), classifies it as CWE-119, and lists tcpdump versions through 4.8.1 as vulnerable. The CVE description states the issue is different from CVE-2016-8575. Downstream remediation references are present for Debian, Red Hat, and Gentoo, supporting broad package-level impact.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-5482 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-5482
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-5482 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-5482
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2017:1871
-
Source reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/201702-30
-
Source reference
Unverified legacy reference
URL: https://www.mail-archive.com/debian-bugs-dist%40lists.debian.org/msg1494526.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.