CVE-2017-12894 describes a critical buffer over-read vulnerability in tcpdump, affecting versions prior to 4.9.2, specifically within several protocol parsers in addrtoname.c:lookup_bytestring(). This vulnerability carries a CVSS v3 score of 9.8 (CRITICAL), indicating it can be exploited remotely with low attack complexity and no user interaction, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and a FAUCET Risk Score of 80/100, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal, with one article noting its inclusion in a batch of 90 tcpdump fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.