CVE-2017-12990Infinite Loop in Tcpdump

Severity
9.8CRITICALNVD
OSV7.5
EPSS
1.1%
top 21.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 13

Description

The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bugs in print-isakmp.c, several functions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

debiandebian/tcpdump< tcpdump 4.9.2-1 (bookworm)
Debiantcpdump/tcpdump< 4.9.2-1+3
Ubuntutcpdump/tcpdump< 4.9.2-0ubuntu0.14.04.1+1
NVDtcpdump/tcpdump4.9.1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-h7v2-cvh5-xv63: The ISAKMP parser in tcpdump before 42022-05-13
OSV
CVE-2017-12990: The ISAKMP parser in tcpdump before 42017-09-14
OSV
tcpdump vulnerabilities2017-09-14

📋Vendor Advisories

5
Apple
CVE-2017-12990: macOS High Sierra 10.13.1, Security Update 2017-001 Sierra, and Security Update 2017-004 El Capitan2017-10-31
Ubuntu
tcpdump vulnerabilities2017-09-14
Ubuntu
tcpdump vulnerabilities2017-09-14
Red Hat
tcpdump: Infinite loop due to bugs in print-isakmp.c, several functions in ISAKMP parser2017-09-13
Debian
CVE-2017-12990: tcpdump - The ISAKMP parser in tcpdump before 4.9.2 could enter an infinite loop due to bu...2017

💬Community

2
Bugzilla
CVE-2017-12990 tcpdump: Infinite loop due to bugs in print-isakmp.c, several functions in ISAKMP parser2017-09-11
Bugzilla
CVE-2017-11541 CVE-2017-11542 CVE-2017-11543 CVE-2017-11544 CVE-2017-11545 CVE-2017-12893 CVE-2017-12894 CVE-2017-12895 CVE-2017-12896 CVE-2017-12897 CVE-2017-12898 CVE-2017-12899 CVE-2017-12900 CVE-22017-07-26
CVE-2017-12990 — Infinite Loop in Debian Tcpdump | cvebase