The Rx protocol parser in tcpdump before 4.9.2 has a buffer over-read in print-rx.c:ubik_print().
[
{
"signature_version": "v1",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/aa0858100096a3490edf93034a80e66a4d61aad5",
"deprecated": false,
"id": "CVE-2017-13049-898e826f",
"target": {
"file": "print-rx.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"63843967416797515597997360256191610585",
"133301679981428652742298382070126201795",
"142469259638275130741321571653572169640",
"249635146459317272050707311722977492639"
]
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/aa0858100096a3490edf93034a80e66a4d61aad5",
"deprecated": false,
"id": "CVE-2017-13049-9a5ffba1",
"target": {
"function": "ubik_print",
"file": "print-rx.c"
},
"digest": {
"function_hash": "282429154980108806745126512576029203986",
"length": 1964.0
},
"signature_type": "Function"
}
]