{"id":"CVE-2017-12897","details":"The ISO CLNS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isoclns_print().","modified":"2026-04-11T04:47:26.074674Z","published":"2017-09-14T06:29:00.357Z","related":["MGASA-2017-0335","SUSE-SU-2017:2854-1","SUSE-SU-2019:14191-1","openSUSE-SU-2024:11425-1"],"references":[{"type":"WEB","url":"http://www.securitytracker.com/id/1039307"},{"type":"WEB","url":"https://support.apple.com/HT208221"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3971"},{"type":"ADVISORY","url":"http://www.tcpdump.org/tcpdump-changes.txt"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHEA-2018:0705"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201709-23"},{"type":"FIX","url":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/the-tcpdump-group/tcpdump","events":[{"introduced":"0"},{"last_affected":"993a67c8e648bc8b19881e29a60f41273cfbee7b"},{"fixed":"1dcd10aceabbc03bf571ea32b892c522cbe923de"}],"database_specific":{"versions":[{"introduced":"0"},{"last_affected":"4.9.1"}]}}],"versions":["tcpdump-3.5.1","tcpdump-3.6.1","tcpdump-3.7.1","tcpdump-3.8-bp","tcpdump-4.5.0","tcpdump-4.6.0","tcpdump-4.6.0-bp","tcpdump-4.7.0-bp","tcpdump-4.9.0","tcpdump-4.9.0-bp","tcpdump-4.9.1"],"database_specific":{"vanir_signatures":[{"digest":{"function_hash":"93820044114081734725633572112346788921","length":2411},"deprecated":false,"target":{"file":"print-gre.c","function":"gre_print_0"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-022360e4","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["137587822891245808538438163163170620154","62161595775300235834678384372209215956","262691547227544213199233514488467919357","273572954119360607089325953082792996431","137587822891245808538438163163170620154","62161595775300235834678384372209215956","262691547227544213199233514488467919357","273572954119360607089325953082792996431","223516668058173852625292326389954803351","157997619626629700167466142756296800438","187116946578553223729363498000307072616","173945240552564407975455067630134488747","205158362243854751174048902960663926621","202345866189892450122886260016767435441","221609318441420667691609226039316801896","180034154266275654206982313885793011931","236557984866370494810017249290010452567","75161061119265002226712993032464931126","324356040347124293394532348487862362704","197325807731200251336765305412710538594","311093851271786829399836998075936000688","205158362243854751174048902960663926621","202345866189892450122886260016767435441","221609318441420667691609226039316801896","180034154266275654206982313885793011931","236557984866370494810017249290010452567","187125409226171684176392095659302640286","161492522511330632207725653986096939889","332688025886341835733847061558135400031","62571283732035778076904656088471665654","187125409226171684176392095659302640286","161492522511330632207725653986096939889","332688025886341835733847061558135400031","299437877487082603495878491178036870634"]},"deprecated":false,"target":{"file":"print-juniper.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-05e3b872","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["26329136187128549422927735621376334525","167510685006741106754839009757385628402","196366665111646926998710213418420139718","329859615098995908688865750420722502191"]},"deprecated":false,"target":{"file":"netdissect.h"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-0fc4c6be","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["149643242587254554262032414969485332915","205475188816929805914870052626351235335","53860238244176666843771311546532756641","314039680516477542175594827385099511391"]},"deprecated":false,"target":{"file":"print-fr.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-383ad7a0","signature_version":"v1"},{"digest":{"function_hash":"81465525670873947704337395081325173564","length":1256},"deprecated":false,"target":{"file":"print-isoclns.c","function":"isoclns_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-398087a5","signature_version":"v1"},{"digest":{"function_hash":"63556931620974473482081836890453567584","length":1267},"deprecated":false,"target":{"file":"print-ppp.c","function":"handle_ppp"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-47af54bc","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["53756605576367161825115910582154368979","104334051113704502627343080854801385234","71665722405796285711258879488090617041","166144038063616045262340022356341301867","68838115350250101287714182303426437477","67484947014314528609578953429925405619"]},"deprecated":false,"target":{"file":"print-chdlc.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-4a3cbfec","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["204865545266841560590881317746919303201","134051600607657007166123352493459719447","82472340052331388888753843804118423828","307200225550039400161670531514935009897"]},"deprecated":false,"target":{"file":"print-ether.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-58d900bc","signature_version":"v1"},{"digest":{"function_hash":"271972235427279524839338405591945313510","length":1107},"deprecated":false,"target":{"file":"print-juniper.c","function":"juniper_atm2_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-5ba0e936","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["315669636927543786997800639652210595672","222323132755767671851019118823241104082","53587836157672210549011384541101036624","14739951591869089003803885041127289549"]},"deprecated":false,"target":{"file":"print-atm.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-6e41a86c","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["5439834071782243854422732283436943925","4295980330533516694280273190834778476","40815466299439327240212006840197595817","309848497948245896047426020018876280981"]},"deprecated":false,"target":{"file":"print-mpls.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-7a6973ac","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["104017817957546053392950440107524506864","174760186768028067975593085364661796397","269461404914190857435112620443212579180","137210767563691048307167424874641391547"]},"deprecated":false,"target":{"file":"print-null.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-7f0ad74c","signature_version":"v1"},{"digest":{"function_hash":"178063235761562717930162753958791160935","length":2676},"deprecated":false,"target":{"file":"print-ether.c","function":"ethertype_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-8d396ae6","signature_version":"v1"},{"digest":{"function_hash":"263413542399240025527427494405040491303","length":4697},"deprecated":false,"target":{"file":"print-llc.c","function":"llc_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-8d7773b3","signature_version":"v1"},{"digest":{"function_hash":"250877498406377720938094715659607669112","length":1517},"deprecated":false,"target":{"file":"print-juniper.c","function":"juniper_mfr_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-9341d132","signature_version":"v1"},{"digest":{"function_hash":"157258781401340107241127521794074636171","length":1995},"deprecated":false,"target":{"file":"print-mpls.c","function":"mpls_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-99f42d78","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["277831121977609820042689260730692974775","255419524458318330235632167942701493683","110484629614421908869302859637030709199","207246850440338317222375392423463699555"]},"deprecated":false,"target":{"file":"print-ppp.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-9c393ddb","signature_version":"v1"},{"digest":{"function_hash":"173589911762099619188759223252155746508","length":2394},"deprecated":false,"target":{"file":"print-fr.c","function":"fr_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-9c85c11c","signature_version":"v1"},{"digest":{"function_hash":"296279740794663632987306692169747888559","length":812},"deprecated":false,"target":{"file":"print-juniper.c","function":"juniper_mlfr_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-9e75f4d2","signature_version":"v1"},{"digest":{"function_hash":"114922958061577137714823970107311298244","length":1290},"deprecated":false,"target":{"file":"print-juniper.c","function":"juniper_mlppp_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-a04a6091","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["253171066741418948287971816994353285903","78105328798716988892265708244232047534","316424413726330663948031467699737057328","129679793842356519961408873865601342501"]},"deprecated":false,"target":{"file":"print-gre.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-b068b302","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["240638142631912293894829269107976843645","265984557819110366856196269050951605575","86681691179805692301433878605138613632","226814076584129385485203358259489822230","311238399830420466186827485823977587699","156138716120241531439073138342065876330","40947904021558979050261566760224768296","292989439936600316628512792981861000939","221285104749620863293344873471110163737","204769009705743907897199460716316864017","489308055307353223654175101301431392","189855499144741036121337323769389178111","237139675962055335450537207595151138804","259979070775971532380314644674432498646","217114864630934603526211743567341871725","20329223160173212960791124420711911402","322739194800317899508922719149502734272","46808251417069286042789721339672382523","155688229815353625353897306489479466743","222919411964632160634737390526929668711"]},"deprecated":false,"target":{"file":"print-isoclns.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-c0f1422c","signature_version":"v1"},{"digest":{"function_hash":"161764293815385750416687340278517322992","length":1005},"deprecated":false,"target":{"file":"print-atm.c","function":"atm_if_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-d23ad3c6","signature_version":"v1"},{"digest":{"function_hash":"170603802685891635145332729617177806863","length":1096},"deprecated":false,"target":{"file":"print-null.c","function":"null_if_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-d6f29da0","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["18861617248317870015706345959697661364","215386114515995834119239096190852292525","320846012810066643787789791090289188098","316510964237516852056861634506950609981"]},"deprecated":false,"target":{"file":"print-llc.c"},"signature_type":"Line","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-ea118469","signature_version":"v1"},{"digest":{"function_hash":"52672609724261384853824162082809341247","length":1431},"deprecated":false,"target":{"file":"print-chdlc.c","function":"chdlc_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-ecc72f06","signature_version":"v1"},{"digest":{"function_hash":"124929021604936634209558365452301685015","length":811},"deprecated":false,"target":{"file":"print-juniper.c","function":"juniper_atm1_print"},"signature_type":"Function","source":"https://github.com/the-tcpdump-group/tcpdump/commit/1dcd10aceabbc03bf571ea32b892c522cbe923de","id":"CVE-2017-12897-f7d6ce95","signature_version":"v1"}],"vanir_signatures_modified":"2026-04-11T04:47:26Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-12897.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}