In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-9351.json"