The BGP parser in tcpdump before 4.9.2 has a buffer over-read in print-bgp.c:decodertrouting_info().
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"160627892026054568692942229567442341921",
"339745157091026129951097035969839045377",
"171164312225466190731673413538583417812",
"338434652609649649762481319754872029766",
"318623214972556097439308677056352126901",
"181962824181316492070464842165944682895",
"179224163089938257283993679369455407848",
"152979993405555006800728741910276687503",
"6341194129947448493206295838362526776",
"228699489141087605360419518509959589675",
"224172182254023710090887854635509463820",
"207981756214880103682589886205077033813",
"37260282088682639420260104172113508776",
"127774720549155218906593248018784916889",
"49601202798458118772887576200474662480",
"336746571422072494570599502502597692503",
"281031328299510336607448783935569572478",
"170162391415913983300595446194134979557",
"257755541479794452314941300751186482806",
"287085937901166469444212952567532749897",
"302063960484327276653007180539068524994",
"216666460335740045161839726003017217420"
],
"threshold": 0.9
},
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/bd4e697ebd6c8457efa8f28f6831fc929b88a014",
"target": {
"file": "print-bgp.c"
},
"id": "CVE-2017-13053-09b5c9a6"
},
{
"deprecated": false,
"digest": {
"function_hash": "54486518121344525426284242223113053383",
"length": 808.0
},
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/bd4e697ebd6c8457efa8f28f6831fc929b88a014",
"target": {
"function": "decode_rt_routing_info",
"file": "print-bgp.c"
},
"id": "CVE-2017-13053-ee8c6e37"
}
]