The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:bgpattrprint().
{ "vanir_signatures": [ { "id": "CVE-2017-13046-837529a8", "signature_type": "Line", "target": { "file": "print-bgp.c" }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d10a0f980fe8f9407ab1ffbd612641433ebe175e", "digest": { "threshold": 0.9, "line_hashes": [ "119724313630115847287380973762516868193", "205038692229712768246849612710398851317", "86166909227532086198957134701272916612", "49921369663580181265209702153625237618", "157572217689921242205809511079767086278", "119159450301622203133947757984445251444", "55845719694059390194956897470651587957" ] }, "deprecated": false, "signature_version": "v1" }, { "id": "CVE-2017-13046-cb4364f6", "signature_type": "Function", "target": { "file": "print-bgp.c", "function": "bgp_attr_print" }, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/d10a0f980fe8f9407ab1ffbd612641433ebe175e", "digest": { "function_hash": "42190185194711108551981830729679661694", "length": 25664.0 }, "deprecated": false, "signature_version": "v1" } ] }