The telnet parser in tcpdump before 4.9.2 has a buffer over-read in print-telnet.c:telnet_parse().
[
{
"digest": {
"length": 2231.0,
"function_hash": "3174917664439056968835398981928661099"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/8934a7d6307267d301182f19ed162563717e29e3",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "telnet_parse",
"file": "print-telnet.c"
},
"id": "CVE-2017-12988-29bcf351",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"287370690541610701360793441734267325906",
"57100495640581646232050786450472498004",
"147460875534616350229031090682247365674",
"224198201307392529602952091072839023317"
],
"threshold": 0.9
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/8934a7d6307267d301182f19ed162563717e29e3",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "print-telnet.c"
},
"id": "CVE-2017-12988-3fffa537",
"signature_type": "Line"
}
]