The OSPFv3 parser in tcpdump before 4.9.2 has a buffer over-read in print-ospf6.c:ospf6decodev3().
[
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d",
"signature_version": "v1",
"digest": {
"line_hashes": [
"177234693885706553521065521425985454797",
"320814155312291512319922962358747287446",
"39658884872038436659013766633841866662"
],
"threshold": 0.9
},
"target": {
"file": "print-ospf6.c"
},
"id": "CVE-2017-13036-19ca6218",
"deprecated": false,
"signature_type": "Line"
},
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d",
"signature_version": "v1",
"digest": {
"function_hash": "333334224769914758278074725097894681532",
"length": 3272.0
},
"target": {
"function": "ospf6_decode_v3",
"file": "print-ospf6.c"
},
"id": "CVE-2017-13036-368f70a9",
"deprecated": false,
"signature_type": "Function"
}
]