The HNCP parser in tcpdump before 4.9.2 has a buffer over-read in print-hncp.c:dhcpv4_print().
{ "vanir_signatures": [ { "id": "CVE-2017-13044-8864f0fa", "signature_type": "Line", "digest": { "threshold": 0.9, "line_hashes": [ "275315002644260521737434246687671016348", "257725903016291485571226794152291520375", "193435317015978155096143487023084826612", "72023467591269345673825744661742944172", "7438969905673721079956049704532274857", "328610337025240070233085808624488010845", "122510169073445473314955408651019914455", "198335211804964431639064000431166616807" ] }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/c2f6833dddecf2d5fb89c9c898eee9981da342ed", "target": { "file": "print-hncp.c" }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2017-13044-e9f33ee1", "signature_type": "Function", "digest": { "function_hash": "215514799166611943461803832222014483321", "length": 975.0 }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/c2f6833dddecf2d5fb89c9c898eee9981da342ed", "target": { "file": "print-hncp.c", "function": "dhcpv4_print" }, "deprecated": false, "signature_version": "v1" } ] }