The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniperparseheader().
{ "vanir_signatures": [ { "target": { "file": "print-juniper.c" }, "deprecated": false, "digest": { "threshold": 0.9, "line_hashes": [ "234264056026321927470504702073393842305", "52325095989268154129897589357186505211", "268770971147915891867268879560444734893" ] }, "id": "CVE-2017-13004-8dfcb5ea", "signature_type": "Line", "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/42073d54c53a496be40ae84152bbfe2c923ac7bc" }, { "target": { "function": "juniper_parse_header", "file": "print-juniper.c" }, "deprecated": false, "digest": { "length": 6952.0, "function_hash": "181019605112102346093767750243993717453" }, "id": "CVE-2017-13004-c5123741", "signature_type": "Function", "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/42073d54c53a496be40ae84152bbfe2c923ac7bc" } ] }