The OSPFv3 parser in tcpdump before 4.9.2 has a buffer over-read in print-ospf6.c:ospf6decodev3().
{ "vanir_signatures": [ { "digest": { "threshold": 0.9, "line_hashes": [ "177234693885706553521065521425985454797", "320814155312291512319922962358747287446", "39658884872038436659013766633841866662" ] }, "target": { "file": "print-ospf6.c" }, "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d", "signature_version": "v1", "id": "CVE-2017-13036-19ca6218", "signature_type": "Line" }, { "digest": { "length": 3272.0, "function_hash": "333334224769914758278074725097894681532" }, "target": { "file": "print-ospf6.c", "function": "ospf6_decode_v3" }, "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d", "signature_version": "v1", "id": "CVE-2017-13036-368f70a9", "signature_type": "Function" } ] }