The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv4_print().
[
{
"signature_version": "v1",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/c2f6833dddecf2d5fb89c9c898eee9981da342ed",
"deprecated": false,
"id": "CVE-2017-13044-8864f0fa",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"275315002644260521737434246687671016348",
"257725903016291485571226794152291520375",
"193435317015978155096143487023084826612",
"72023467591269345673825744661742944172",
"7438969905673721079956049704532274857",
"328610337025240070233085808624488010845",
"122510169073445473314955408651019914455",
"198335211804964431639064000431166616807"
]
},
"target": {
"file": "print-hncp.c"
}
},
{
"signature_version": "v1",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/c2f6833dddecf2d5fb89c9c898eee9981da342ed",
"deprecated": false,
"id": "CVE-2017-13044-e9f33ee1",
"signature_type": "Function",
"digest": {
"length": 975.0,
"function_hash": "215514799166611943461803832222014483321"
},
"target": {
"function": "dhcpv4_print",
"file": "print-hncp.c"
}
}
]