The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldpmgmtaddrtlvprint().
{ "vanir_signatures": [ { "signature_type": "Function", "digest": { "length": 896.0, "function_hash": "227171919269344585260810792131172284102" }, "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/a77ff09c46560bc895dea11dc9fe643486b056ac", "id": "CVE-2017-13027-4cb5f103", "target": { "file": "print-lldp.c", "function": "lldp_mgmt_addr_tlv_print" }, "deprecated": false }, { "signature_type": "Line", "digest": { "line_hashes": [ "196870506007357023015671265219120159778", "241568516534298499615723573392044322647", "115079262041967538289396510249331898541", "38941896934750980623508760405129589712" ], "threshold": 0.9 }, "signature_version": "v1", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/a77ff09c46560bc895dea11dc9fe643486b056ac", "id": "CVE-2017-13027-6f48727e", "target": { "file": "print-lldp.c" }, "deprecated": false } ] }