Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Ettercap | Ettercap-project | 0.8.1 (including) | 0.8.1 (including) |
| Ettercap | Ubuntu | lucid | * |
| Ettercap | Ubuntu | precise | * |
| Ettercap | Ubuntu | trusty | * |
| Ettercap | Ubuntu | upstream | * |
| Ettercap | Ubuntu | utopic | * |