The ISO IS-IS parser in tcpdump before 4.9.2 has a buffer over-read in print-isoclns.c:isisprintisreachsubtlv().
[ { "signature_type": "Line", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/5d0d76e88ee2d3236d7e032589d6f1d4ec5f7b1e", "signature_version": "v1", "target": { "file": "print-isoclns.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "268872199209433859824263155583322783210", "100226478625329499165310110478394734424", "298920727269548542059712833551838803430", "93346281306487972737854753147262423864", "288212607973428931597131834176087760944", "195259105033107390020991586578507116901", "172721198790665924701846368456583485320", "323540136499082413077282677922287560180" ] }, "id": "CVE-2017-13055-34f503c7" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/5d0d76e88ee2d3236d7e032589d6f1d4ec5f7b1e", "signature_version": "v1", "target": { "function": "isis_print_is_reach_subtlv", "file": "print-isoclns.c" }, "digest": { "function_hash": "178996193233329007737438771165965823642", "length": 4187.0 }, "id": "CVE-2017-13055-6e2d8e6c" } ]