The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decodemulticastvpn().
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"53227809589211465896634588749898187477",
"231239712511084767951244738715803454864",
"319498755644165660555995688040940483627",
"202459409726354006927026744952598649225",
"274833383469961596765950243673306359418",
"75987654742839677976118604675906881517",
"96396475744034912349682510307446886711",
"112720235934996099310435053372522494032",
"271044335859582714288395084601945439148",
"255635385683405905392987769798128497201"
]
},
"target": {
"file": "print-bgp.c"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/d515b4b4a300479cdf1a6e0d1bb95bc1f9fee514",
"id": "CVE-2017-13043-42b459b9",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "138708358530088317450719031790421752977",
"length": 2297.0
},
"target": {
"file": "print-bgp.c",
"function": "decode_multicast_vpn"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/d515b4b4a300479cdf1a6e0d1bb95bc1f9fee514",
"id": "CVE-2017-13043-f24f8e3a",
"deprecated": false,
"signature_version": "v1"
}
]