CVE-2017-13036 describes a critical buffer over-read vulnerability in the OSPFv3 parser of tcpdump versions prior to 4.9.2, specifically within the print-ospf6.c:ospf6_decode_v3() function. This flaw carries a CVSS v3.0 score of 9.8 (Critical), indicating it can be exploited remotely with low complexity and without user interaction, leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, the vulnerability has garnered some community discussion and media coverage, including a mention in a Hackernews article about tcpdump fixes.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.1CPE matchmatch criteria | cpe:2.3:a:tcpdump:tcpdump:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.