The VTP parser in tcpdump before 4.9.2 has a buffer over-read in print-vtp.c:vtp_print().
[ { "signature_type": "Line", "id": "CVE-2017-13033-61f49254", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/ae83295915d08a854de27a88efac5dd7353e6d3f", "signature_version": "v1", "target": { "file": "print-vtp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "234336878474384708427175196259430270535", "185090606927285420763559402886862331140", "3780169356105581229990706202763787467", "250800490314488946561720263577602162734", "38489243769677278899846523235484437184", "217751946776508949722643018369109002226", "167217743291130769285130425897259385285", "160661039750792297514091039608789980211", "299904914281181874671852343287383695598", "294295762119006200642838093822093720256", "51793332749787623785708044540402518822", "221595526667411965031476357434276973527", "28585970382549092817537657524558281612", "48880856084475882486612265500917841867", "219369565652451775945180830962287503656", "49622631095616427425399166084329673051", "301646005299377750940042169675105598441", "209835676795715574017276545625986430838", "249067595737137251435906706991688136005", "257749549829035578916164448237708058630", "25082856622630797010135928507860790789", "322265107567926162243468115916470677168", "221190823897913991896717717835053811810", "236696921381856744786511876689149967376", "214759737524340956306142570987495778045", "157451052513537134265781155149054111742", "200497928263352163265575758542644970841", "21659901588265208639679728084761607095", "93930527709640649060810043454665821875", "65428167623821792856216171170630675501", "80137289626484946392803296510637206088", "124453767287658770157411329732186737297", "114806450943799181472085967951376188597", "212245999492970598031618253232348373913", "53920735607600953379829584758313512348", "146126711136959006829663533470983102918", "250173786276234710535349976523048795066", "154552114130685839040237752422276842886", "228859127725935890781299516631617379535", "336142017184918436745318978981602592319", "15676406977952667952107904922384930192", "162389863325080985480125046683303842556", "324877180256121209245064226866850967117", "101099621051801027355471530533157586340", "33818721452916011171740441940644250385", "269041101698943756489461518082616989399", "223312472076029283042823774689992437874", "47669296546417140455718950439665022326", "267796547843278786405092873905146049725", "193508648052424921212463802232737530304", "137265730505187910091304542419850159895", "4858398236585165638041062248575780845", "219474262869408750873877953161188692165", "106906721357451018710011760339097809389", "96593516364094931645831591774534219996" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2017-13033-743e0d8f", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/ae83295915d08a854de27a88efac5dd7353e6d3f", "signature_version": "v1", "target": { "function": "vtp_print", "file": "print-vtp.c" }, "digest": { "function_hash": "64132703562053676549992576139838630795", "length": 3619.0 }, "deprecated": false } ]