lmpprintdatalinksubobjs() in print-lmp.c in tcpdump before 4.9.3 lacks certain bounds checks.
{ "vanir_signatures": [ { "signature_version": "v1", "target": { "function": "lmp_print", "file": "print-lmp.c" }, "signature_type": "Function", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/0b661e0aa61850234b64394585cf577aac570bf4", "deprecated": false, "digest": { "length": 16001.0, "function_hash": "317593515115105228887252178779934219332" }, "id": "CVE-2019-15166-1c0fe6a2" }, { "signature_version": "v1", "target": { "function": "lmp_print_data_link_subobjs", "file": "print-lmp.c" }, "signature_type": "Function", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/0b661e0aa61850234b64394585cf577aac570bf4", "deprecated": false, "digest": { "length": 1629.0, "function_hash": "56728099878522943966771205769458089191" }, "id": "CVE-2019-15166-4dc08ec8" }, { "signature_version": "v1", "target": { "file": "print-lmp.c" }, "signature_type": "Line", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/0b661e0aa61850234b64394585cf577aac570bf4", "deprecated": false, "digest": { "line_hashes": [ "128794166514168293160180237581560217768", "201613703415597722734769401334141704858", "339130882870408496641834802134909185594", "235073896539120481747199018116881760590", "163132803292878940909172269588812675267", "285396999172373070146452458957009056712", "337613375715034881910373520806617588402", "252164173148962321363035688327396805167", "140274291513575747473346185559406076220", "154895803691310732092652708892302139881", "156658199997456521470855288867652537193", "288390540185400500374346780989774328449", "162255691850645826192088068313465360259", "280473666793893309371393293894271271764", "621377116330808196783741792000679427", "209431810772896011560509698579064092021", "248691865026137488520374315519844730617", "101830868356885509206751764086381481861", "122375201020930007016177738857450174915", "228137541529557716054253361517962505201", "38317540946630277043568892539288130734", "134419992717111994516939127216239324818", "217860894883882309549795670900558172620", "257689291168032079526261745880258641015", "235519552579945636232304063200744920598", "507582271940074313616347463987491159", "282441906894834765221593213990459923766" ], "threshold": 0.9 }, "id": "CVE-2019-15166-677049e0" } ] }