The ICMP parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp.c:icmp_print().
{ "vanir_signatures": [ { "digest": { "length": 8722.0, "function_hash": "19800174575102805042611660303573113087" }, "signature_type": "Function", "signature_version": "v1", "id": "CVE-2017-13012-21e482c1", "deprecated": false, "target": { "file": "print-icmp.c", "function": "icmp_print" }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/8509ef02eceb2bbb479cea10fe4a7ec6395f1a8b" }, { "digest": { "threshold": 0.9, "line_hashes": [ "16605384045187996344678746097637230051", "318504507158277911234453146149903866219", "180550245104974181182765376815190536029", "168705065743361993563755765266476309596" ] }, "signature_type": "Line", "signature_version": "v1", "id": "CVE-2017-13012-ecf4fb3c", "deprecated": false, "target": { "file": "print-icmp.c" }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/8509ef02eceb2bbb479cea10fe4a7ec6395f1a8b" } ] }