The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv6_print().
[ { "signature_type": "Line", "id": "CVE-2017-13042-1f39d2d2", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/39582c04cc5e34054b2936b423072fb9df2ff6ef", "signature_version": "v1", "target": { "file": "print-hncp.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "271291941724673615232417132637518384269", "26677000921868014255256920594760141729", "309734749288011757570807663444403848149", "10411421256108217757264424966383925420", "225917642202699590963619218400178643302", "253769488728218380134974015218682599142", "172467566841741380615140722830442186602", "315415057899283192826447604930330826938" ] }, "deprecated": false }, { "signature_type": "Function", "id": "CVE-2017-13042-4bc5d803", "source": "https://github.com/the-tcpdump-group/tcpdump/commit/39582c04cc5e34054b2936b423072fb9df2ff6ef", "signature_version": "v1", "target": { "function": "dhcpv6_print", "file": "print-hncp.c" }, "digest": { "function_hash": "314864348627341437947351339301548824680", "length": 1003.0 }, "deprecated": false } ]