The OSPFv3 parser in tcpdump before 4.9.2 has a buffer over-read in print-ospf6.c:ospf6decodev3().
{ "vanir_signatures": [ { "id": "CVE-2017-13036-19ca6218", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d", "deprecated": false, "signature_version": "v1", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "177234693885706553521065521425985454797", "320814155312291512319922962358747287446", "39658884872038436659013766633841866662" ] }, "target": { "file": "print-ospf6.c" } }, { "id": "CVE-2017-13036-368f70a9", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/88b2dac837e81cf56dce05e6e7b5989332c0092d", "deprecated": false, "signature_version": "v1", "signature_type": "Function", "digest": { "length": 3272.0, "function_hash": "333334224769914758278074725097894681532" }, "target": { "file": "print-ospf6.c", "function": "ospf6_decode_v3" } } ] }