The RIPng parser in tcpdump before 4.9.2 has a buffer over-read in print-ripng.c:ripng_print().
[
{
"id": "CVE-2017-12992-2c9a53c4",
"deprecated": false,
"digest": {
"line_hashes": [
"145011960578676187190522856897951719548",
"68833668964147764681556503830646186492",
"132455491812760869054111622570305555972",
"126162085333803815421256449533947472978",
"161950254408469534203688521263539201779",
"291969377294933995305632931370179605779",
"311335317768211373077523213940334272565",
"119143765914055694664790462058037241110",
"249412749419994621686251970667106346501",
"17703837012563150817683337059856441650",
"271260656894934795050231160669094693337",
"194140407582032183142911055229012523105",
"63532193004470732873944719335940200246",
"263587324879592468399210308175351254896",
"250035250871898872353359668863568321485",
"11729995337693597927532829350732592726",
"79777794702143231111726165531017001374",
"227764823265938370752659080457607232506",
"316211723715495727675960233381169116434",
"290918270883614232407101154736592135224",
"148369751227149032367162498584577212946",
"296454163754821851811394671787923263830",
"247953697254394067248211526914756555150",
"20081520318597076040779482671061381318",
"79067456189471899770129230062283742500",
"169784328491013732954537542208116806324",
"65564127360897895593941591659187662132",
"45493709711254289905911930232854378944",
"329832505859404771671704660238823846873",
"78010201966022929391847303543564403102",
"210650300260306109153918131875729415520",
"329714634856392951800474747453609450440",
"166356431569109017338877984111411221897",
"201921010803174875424867882994657899744",
"307674201043526334913670470676571311763",
"287187161220828954116676899867151471399",
"74191072770118116625531037622903037524",
"178568978481670452024143841630284996722",
"95756053650299352018573947197419596475",
"72481464796221961295717720594934629266",
"316332891621041336420109920261280039727",
"324574641808218408084491116027904351549",
"31706366369084527888470892122731748657",
"45493709711254289905911930232854378944",
"329832505859404771671704660238823846873",
"78010201966022929391847303543564403102",
"210650300260306109153918131875729415520",
"259282887918921681503497988831457087436",
"71205707885639385980742978846700020452",
"258876772238989411959633987318151945520",
"272644712158999840409686385673703665921",
"142950367412934176658633419630266979845",
"239327953385347902608281824868391789485",
"273141769668651179553786563319296924654",
"221748673248249420380181043882830253078",
"197661951466703393096813546984025198735",
"147421415722448789454632195848902550226",
"56311323172732759005821444204934115110",
"456117483134224984127215140596160077"
],
"threshold": 0.9
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e942fb84fbe3a73a98a00d2a279425872b5fb9d2",
"target": {
"file": "print-ripng.c"
},
"signature_version": "v1",
"signature_type": "Line"
},
{
"id": "CVE-2017-12992-4fbac94a",
"deprecated": false,
"digest": {
"length": 1947.0,
"function_hash": "208498605873048850325236660778712300844"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e942fb84fbe3a73a98a00d2a279425872b5fb9d2",
"target": {
"function": "ripng_print",
"file": "print-ripng.c"
},
"signature_version": "v1",
"signature_type": "Function"
}
]