CVE Vulnerabilities

CVE-2014-9376

Published: Dec 19, 2014 | Modified: Feb 26, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Integer underflow in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

Affected Software

Name Vendor Start Version End Version
Ettercap Ettercap-project 0.8.1 (including) 0.8.1 (including)
Ettercap Ubuntu lucid *
Ettercap Ubuntu precise *
Ettercap Ubuntu trusty *
Ettercap Ubuntu upstream *
Ettercap Ubuntu utopic *

References