The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().
{ "vanir_signatures": [ { "id": "CVE-2017-13020-026c7220", "digest": { "length": 3581.0, "function_hash": "189016524707002346352972255880292324190" }, "signature_type": "Function", "target": { "file": "print-vtp.c", "function": "vtp_print" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/c5dd7bef5e54da5996dc4713284aa6266ae75b75" }, { "id": "CVE-2017-13020-2ab6a4b0", "digest": { "threshold": 0.9, "line_hashes": [ "125022989782758936635811793572214241896", "23704956859129995782856183300742717689", "92772574987655080578909755517117719729", "274532621181560370364875356327450785170", "314179516151983467578521723028472741904", "307226669826132609380417879322844317844" ] }, "signature_type": "Line", "target": { "file": "print-vtp.c" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/c5dd7bef5e54da5996dc4713284aa6266ae75b75" } ] }