There seems to be a heap-based buffer overread while running tcpdump on a crafted pcap file. A similar behavior is seen when tcpdump is listening on an interface and the contents of this file is relayed over the network.
Please find the detailed report on github
https://github.com/the-tcpdump-group/tcpdump/issues/645
CVE: https://nvd.nist.gov/vuln/detail/CVE-2017-16808
Heap Over Read