CVE-2014-9378: Input Validation
Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parseline function in mdnsspoof/mdnsspoof.c or (2) base64 encoded password to the dissectorimap function in dissectors/ecimap.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9378?
CVE-2014-9378 has been classified as a high severity vulnerability due to its potential to cause denial of service and arbitrary code execution.
How do I fix CVE-2014-9378?
To fix CVE-2014-9378, users should upgrade to a more recent and patched version of Ettercap as version 0.8.1 is vulnerable.
What are the potential impacts of CVE-2014-9378?
The potential impacts of CVE-2014-9378 include denial of service, crashing the application, and potentially executing arbitrary code.
Which version of Ettercap is affected by CVE-2014-9378?
Ettercap version 0.8.1 is the only version affected by CVE-2014-9378.
Who can exploit CVE-2014-9378?
Remote attackers can exploit CVE-2014-9378 by sending crafted inputs to trigger the vulnerability.