Critical severity9.8NVD Advisory· Published Sep 14, 2017· Updated May 13, 2026
CVE-2017-12896
CVE-2017-12896
Description
The ISAKMP parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:isakmp_rfc3948_print().
Affected products
7cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.6:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux_server_aus:7.7:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- github.com/the-tcpdump-group/tcpdump/commit/f76e7feb41a4327d2b0978449bbdafe98d4a3771nvdIssue TrackingPatchThird Party Advisory
- www.debian.org/security/2017/dsa-3971nvdThird Party Advisory
- www.securitytracker.com/id/1039307nvdThird Party AdvisoryVDB Entry
- www.tcpdump.org/tcpdump-changes.txtnvdVendor Advisory
- access.redhat.com/errata/RHEA-2018:0705nvdThird Party Advisory
- github.com/the-tcpdump-group/tcpdump/commit/4e430c6b0d8b7e77c7abca7e7afb0c3e727502f2nvdIssue TrackingThird Party Advisory
- security.gentoo.org/glsa/201709-23nvdThird Party Advisory
- support.apple.com/HT208221nvdThird Party Advisory
News mentions
0No linked articles in our index yet.