The RSVP parser in tcpdump before 4.9.2 has a buffer over-read in print-rsvp.c:rsvpobjprint().
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"22994545307458754897656994626798492330",
"81531820141345505351803782676703679312",
"133030223157259475624667370966486060332",
"284899678299805981740848181706040216358",
"161308908561062195879480074122342780251",
"239878996824050096843939914516409043463",
"217788417089968050885773672079123825797",
"123989153505506524120288153715310109819",
"67260305669864238385748467727135085763",
"149622137367389187230432752509684869525",
"48530845722354430662255471007717115283",
"123989153505506524120288153715310109819"
]
},
"target": {
"file": "print-rsvp.c"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/3c8a2b0e91d8d8947e89384dacf6b54673083e71",
"id": "CVE-2017-13048-00870dd2",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Function",
"digest": {
"function_hash": "11491070767884574435411471743345952492",
"length": 24576.0
},
"target": {
"file": "print-rsvp.c",
"function": "rsvp_obj_print"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/3c8a2b0e91d8d8947e89384dacf6b54673083e71",
"id": "CVE-2017-13048-e0a6b25c",
"deprecated": false,
"signature_version": "v1"
}
]