The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
[ { "signature_type": "Function", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/a1eefe986065846b6c69dbc09afd9fa1a02c4a3d", "signature_version": "v1", "target": { "function": "chdlc_print", "file": "print-chdlc.c" }, "digest": { "function_hash": "18473997626305188289610787641774339287", "length": 1191.0 }, "id": "CVE-2017-13687-5fe37d96" }, { "signature_type": "Line", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/a1eefe986065846b6c69dbc09afd9fa1a02c4a3d", "signature_version": "v1", "target": { "file": "print-chdlc.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "23041469025028626655708994872514046480", "185682624390668566289518999731373789192", "130399656142576852722098769055361984304", "288179012368692790876119248817564785718", "80509802461713027056242070324510954026", "200164967453888348616495204665964857812", "340141285087593595047694203826723784403", "95931542610537409090629668797910719396", "146061594311393841028829877545473846386", "316976449553640771577171099658758470672", "182679714387905476500722478013092014188", "305309176765109282260381313260571841251", "184753272182606180824872960112245758904", "102373690910737083653525715600814955755", "257573662026014160002786953934599094073", "319997716853583932194186361496462633090", "146756752595240435015549524888600435478", "216518005961784597210586336451657375979", "91631984454983063730585428333991887203", "22483028605970970210744859483382388660", "108394460453013775475090945721768474259", "51269584062564314715717139383468126793" ] }, "id": "CVE-2017-13687-7a9234e8" }, { "signature_type": "Function", "deprecated": false, "source": "https://github.com/the-tcpdump-group/tcpdump/commit/a1eefe986065846b6c69dbc09afd9fa1a02c4a3d", "signature_version": "v1", "target": { "function": "chdlc_if_print", "file": "print-chdlc.c" }, "digest": { "function_hash": "297324947578263784321719857566373230374", "length": 292.0 }, "id": "CVE-2017-13687-da3924fb" } ]