9.8
CVSSv3

CVE-2017-8366

Published: 30/04/2017 Updated: 04/11/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The strescape function in ec_strings.c in Ettercap 0.8.2 allows remote malicious users to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted filter that is mishandled by etterfilter.

Vulnerable Product Search on Vulmon Subscribe to Product

ettercap project ettercap 0.8.2

Vendor Advisories

Debian Bug report logs - #861604 ettercap: CVE-2017-8366 Package: src:ettercap; Maintainer for src:ettercap is Barak A Pearlmutter <bap@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 1 May 2017 11:21:05 UTC Severity: important Tags: security, upstream Found in version ettercap/1:08 ...
Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash For the stable distribution (jessie), these problems have been fixed in version 1:081-3+deb8u ...
The strescape function in ec_stringsc in Ettercap 082 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly execute arbitrary code via a crafted filter that is mishandled by etterfilter ...