7.5
CVSSv2

CVE-2014-9376

Published: 19/12/2014 Updated: 26/02/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Integer underflow in Ettercap 0.8.1 allows remote malicious users to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5) password to the dissector_TN3270 function in dissectors/ec_TN3270.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ettercap-project ettercap 0.8.1

Vendor Advisories

Debian Bug report logs - #773416 ettercap: CVE-2014-6395 CVE-2014-6396 CVE-2014-9376 CVE-2014-9377 CVE-2014-9378 CVE-2014-9379 CVE-2014-9380 CVE-2014-9381 Package: ettercap; Maintainer for ettercap is Barak A Pearlmutter <bap@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 18 Dec 2014 07:15:0 ...

Exploits

Ettercap versions 080 and 081 suffers from multiple denial of service vulnerabilities ...