The LLDP parser in tcpdump before 4.9.2 has a buffer over-read in print-lldp.c:lldpprivate8023_print().
[
{
"id": "CVE-2017-13054-300125ba",
"signature_type": "Line",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e6511cc1a950fe1566b2236329d6b4bd0826cc7a",
"target": {
"file": "print-lldp.c"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"40120134473430427162105378250836784399",
"276841464808335142979951832153936512125",
"81248931465161144398563922869233075524",
"291003629173390729087005380910355055528"
],
"threshold": 0.9
}
},
{
"id": "CVE-2017-13054-3860df9f",
"signature_type": "Function",
"source": "https://github.com/the-tcpdump-group/tcpdump/commit/e6511cc1a950fe1566b2236329d6b4bd0826cc7a",
"target": {
"file": "print-lldp.c",
"function": "lldp_private_8023_print"
},
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1676.0,
"function_hash": "176126723375690269074487249218962529739"
}
}
]