The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgpattrprint().
[
{
"signature_type": "Line",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/d10a0f980fe8f9407ab1ffbd612641433ebe175e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"119724313630115847287380973762516868193",
"205038692229712768246849612710398851317",
"86166909227532086198957134701272916612",
"49921369663580181265209702153625237618",
"157572217689921242205809511079767086278",
"119159450301622203133947757984445251444",
"55845719694059390194956897470651587957"
]
},
"id": "CVE-2017-13046-837529a8",
"target": {
"file": "print-bgp.c"
}
},
{
"signature_type": "Function",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/d10a0f980fe8f9407ab1ffbd612641433ebe175e",
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "42190185194711108551981830729679661694",
"length": 25664.0
},
"id": "CVE-2017-13046-cb4364f6",
"target": {
"function": "bgp_attr_print",
"file": "print-bgp.c"
}
}
]