Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ettercap | Ettercap-project | 0.8.1 (including) | 0.8.1 (including) |
Ettercap | Ubuntu | lucid | * |
Ettercap | Ubuntu | precise | * |
Ettercap | Ubuntu | trusty | * |
Ettercap | Ubuntu | upstream | * |
Ettercap | Ubuntu | utopic | * |