The ARP parser in tcpdump before 4.9.0 has a buffer overflow in print-arp.c:arp_print().
{ "binaries": [ { "binary_version": "4.9.0-1ubuntu1~ubuntu14.04.1", "binary_name": "tcpdump" }, { "binary_version": "4.9.0-1ubuntu1~ubuntu14.04.1", "binary_name": "tcpdump-dbgsym" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }
{ "binaries": [ { "binary_version": "4.9.0-1ubuntu1~ubuntu16.04.1", "binary_name": "tcpdump" }, { "binary_version": "4.9.0-1ubuntu1~ubuntu16.04.1", "binary_name": "tcpdump-dbgsym" } ], "availability": "No subscription required", "ubuntu_priority": "medium" }