The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
[
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/2b62d1dda41590db29368ec7ba5f4faf3464765a",
"target": {
"file": "print-icmp.c"
},
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"107198856361101451998671042888074049175",
"117070010037379320337705292370104967762",
"116346881088541160103718243430441649863",
"256621475167262262278512615648139740594",
"303531836627226670817309681626562845165",
"89440480514058286812786320391738881908",
"203607696343005560187597129976950900791",
"156548616388147846031577924780589412013",
"258929154696976705831322474467338293819",
"176711468518984865434200542717727827557",
"239256502245257274596097738760381836900",
"87022605688507449365296467334034271979",
"280929190848931064702123616034364856513"
]
},
"signature_type": "Line",
"id": "CVE-2017-12895-528c8c58"
},
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/2b62d1dda41590db29368ec7ba5f4faf3464765a",
"target": {
"file": "print-icmp.c",
"function": "icmp_print"
},
"signature_version": "v1",
"deprecated": false,
"digest": {
"function_hash": "329994029642206011599541272506618978594",
"length": 8593.0
},
"signature_type": "Function",
"id": "CVE-2017-12895-9b50795a"
}
]