In nDPI through 3.2, the packet parsing code is vulnerable to a heap-based buffer over-read in ndpiparsepacketlineinfo in lib/ndpi_main.c.
{ "ubuntu_priority": "medium" }