tcpdump 4.9.0 has a heap-based buffer over-read in the lldp_print function in print-lldp.c, related to util-print.c. https://nvd.nist.gov/vuln/detail/CVE-2017-11541