The PIMv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-pim.c:pimv2_print().
{ "vanir_signatures": [ { "source": "https://github.com/the-tcpdump-group/tcpdump/commit/6fca58f5f9c96749a575f52e20598ad43f5bdf30", "signature_type": "Line", "target": { "file": "print-pim.c" }, "id": "CVE-2017-12996-776485a0", "digest": { "threshold": 0.9, "line_hashes": [ "289876505198630046422597044607557754421", "12738731297553397805119067985592723172", "209631195632104447233238997829986229308", "143683784065402934898732859173838843187", "236605646285853497094413697933887831770", "188090322465602506806480921408712883144", "284621384246339058973613918913533801231", "144574507414572194988300722985292034659", "248033844199847269240735567784500022452", "217474381590077364569132290516179265979", "90270771996288021068791626422536679777", "198671772472801033512288081496239296443", "221907743673885976016842209871830504277", "268345896863523104210542952840955488765", "75707969291147740623003097206326306337", "229784963628038062835654329713272340447", "265796041577422769994238701403912831091" ] }, "deprecated": false, "signature_version": "v1" }, { "source": "https://github.com/the-tcpdump-group/tcpdump/commit/6fca58f5f9c96749a575f52e20598ad43f5bdf30", "signature_type": "Function", "target": { "file": "print-pim.c", "function": "pimv2_print" }, "id": "CVE-2017-12996-b18c012d", "digest": { "function_hash": "116608827616405372022811249068572440064", "length": 10381.0 }, "deprecated": false, "signature_version": "v1" } ] }