7.5
CVSSv2

CVE-2014-6396

Published: 19/12/2014 Updated: 26/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap prior to 0.8.1 allows remote malicious users to cause a denial of service and possibly execute arbitrary code via a crafted password length, which triggers a 0 character to be written to an arbitrary memory location.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ettercap-project ettercap

Vendor Advisories

Debian Bug report logs - #773416 ettercap: CVE-2014-6395 CVE-2014-6396 CVE-2014-9376 CVE-2014-9377 CVE-2014-9378 CVE-2014-9379 CVE-2014-9380 CVE-2014-9381 Package: ettercap; Maintainer for ettercap is Barak A Pearlmutter <bap@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 18 Dec 2014 07:15:0 ...