The ISO ES-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:esis_print().
{ "vanir_signatures": [ { "signature_type": "Function", "target": { "file": "print-isoclns.c", "function": "esis_print" }, "id": "CVE-2017-13047-0cb1fcd9", "digest": { "length": 5634.0, "function_hash": "137593675325680048950151535118197409847" }, "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/331530a4076c69bbd2e3214db6ccbe834fb75640", "signature_version": "v1" }, { "signature_type": "Line", "target": { "file": "print-isoclns.c" }, "id": "CVE-2017-13047-e29d18aa", "digest": { "threshold": 0.9, "line_hashes": [ "233554080458593098635603308859377621081", "112702957282669862805989135981883900305", "194841965264777869983963422697751387019", "224742028932444638056559942048204631335", "203752141944845778458301603270476309353", "49036952671533741770067387784105340925", "301923905986448800037454369597122186438", "115831237297856301336884080071585543006" ] }, "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/331530a4076c69bbd2e3214db6ccbe834fb75640", "signature_version": "v1" } ] }