5
CVSSv2

CVE-2014-9381

Published: 19/12/2014 Updated: 26/02/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote malicious users to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ettercap-project ettercap 0.8.1

Vendor Advisories

Debian Bug report logs - #773416 ettercap: CVE-2014-6395 CVE-2014-6396 CVE-2014-9376 CVE-2014-9377 CVE-2014-9378 CVE-2014-9379 CVE-2014-9380 CVE-2014-9381 Package: ettercap; Maintainer for ettercap is Barak A Pearlmutter <bap@debianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 18 Dec 2014 07:15:0 ...