The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldpprivate8023_print().
[
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e6511cc1a950fe1566b2236329d6b4bd0826cc7a",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2017-13054-300125ba",
"digest": {
"threshold": 0.9,
"line_hashes": [
"40120134473430427162105378250836784399",
"276841464808335142979951832153936512125",
"81248931465161144398563922869233075524",
"291003629173390729087005380910355055528"
]
},
"target": {
"file": "print-lldp.c"
}
},
{
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e6511cc1a950fe1566b2236329d6b4bd0826cc7a",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2017-13054-3860df9f",
"digest": {
"function_hash": "176126723375690269074487249218962529739",
"length": 1676.0
},
"target": {
"function": "lldp_private_8023_print",
"file": "print-lldp.c"
}
}
]