CVE-2017-11542 describes a critical heap-based buffer over-read vulnerability in tcpdump version 4.9.0, specifically within the pimv1_print function. This flaw carries a CVSSv3 score of 9.8, indicating a severe risk with network-based exploitation, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability without user interaction. While not listed in CISA's KEV catalog and lacking public exploit code on Metasploit or ExploitDB, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.9.0CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:4.9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.