The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isisprintextdipreach().
{ "vanir_signatures": [ { "signature_type": "Function", "digest": { "length": 2097.0, "function_hash": "4700251838482651931333855815825044859" }, "signature_version": "v1", "id": "CVE-2017-12998-3029c6d8", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/979dcefd7b259e9e233f77fe1c5312793bfd948f", "target": { "function": "isis_print_extd_ip_reach", "file": "print-isoclns.c" }, "deprecated": false }, { "signature_type": "Line", "digest": { "line_hashes": [ "316813098404573189331629809169371758446", "35480589520905794696450125076201941446", "64094114878927935827241812548677571668", "129605050368975718814600418391387225143" ], "threshold": 0.9 }, "signature_version": "v1", "id": "CVE-2017-12998-52adde6e", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/979dcefd7b259e9e233f77fe1c5312793bfd948f", "target": { "file": "print-isoclns.c" }, "deprecated": false } ] }