The ICMPv6 parser in tcpdump before 4.9.2 has a buffer over-read in print-icmp6.c:icmp6_print().
[ { "signature_type": "Line", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/67c7126062d59729cd421bb38f9594015c9907ba", "signature_version": "v1", "target": { "file": "print-icmp6.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "83582845347540620492194701955985557803", "177568430537303103527377166793235341145", "319599135815728648978403099529769882750", "328919621073038910447855633331647472840" ] }, "id": "CVE-2017-13021-52f0872e" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/67c7126062d59729cd421bb38f9594015c9907ba", "signature_version": "v1", "target": { "function": "icmp6_print", "file": "print-icmp6.c" }, "digest": { "function_hash": "88042001857164022284303757811042837602", "length": 8138.0 }, "id": "CVE-2017-13021-fd286838" } ]