The IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isis_print().
{ "vanir_signatures": [ { "source": "https://github.com/the-tcpdump-group/tcpdump/commit/3b32029db354cbc875127869d9b12a9addc75b50", "deprecated": false, "signature_type": "Line", "signature_version": "v1", "target": { "file": "print-isoclns.c" }, "id": "CVE-2017-12999-07b7e813", "digest": { "line_hashes": [ "221379335927267716935625494711152231640", "60841069273530829628615551042433997511", "219864135049501438618523066433208108795", "176736053110694792171157645754613512396" ], "threshold": 0.9 } }, { "source": "https://github.com/the-tcpdump-group/tcpdump/commit/3b32029db354cbc875127869d9b12a9addc75b50", "deprecated": false, "signature_type": "Function", "signature_version": "v1", "target": { "function": "isis_print", "file": "print-isoclns.c" }, "id": "CVE-2017-12999-bf77cd06", "digest": { "function_hash": "338422197554391792423212948341971282058", "length": 24214.0 } } ] }