The BOOTP parser in tcpdump before 4.9.2 has a buffer over-read in print-bootp.c:bootp_print().
[
{
"id": "CVE-2017-13028-58ed485e",
"digest": {
"length": 3436.0,
"function_hash": "191641942336768970108978463546143369055"
},
"signature_type": "Function",
"target": {
"file": "print-bootp.c",
"function": "bootp_print"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/29e5470e6ab84badbc31f4532bb7554a796d9d52",
"signature_version": "v1",
"deprecated": false
},
{
"id": "CVE-2017-13028-bb75e03b",
"digest": {
"line_hashes": [
"265890019195235269348953119208121848886",
"266118006590917550727663599167978466917",
"9412999328135352389876865767975427043"
],
"threshold": 0.9
},
"signature_type": "Line",
"target": {
"file": "print-bootp.c"
},
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/29e5470e6ab84badbc31f4532bb7554a796d9d52",
"signature_version": "v1",
"deprecated": false
}
]