CVE-2017-12989: Tcpdump

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

The RESP parser in tcpdump before 4.9.2 could enter an infinite loop due to a bug in print-resp.c:resp_get_length().

Affected products

  • Tcpdump Tcpdump: up to and including 4.9.1

Published 2017-09-14. Last modified 2026-06-17.