CVE-2014-9379: Buffer Overflow
The radiusgetattribute function in dissectors/ecradius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9379?
The severity of CVE-2014-9379 is considered critical due to its potential to cause remote denial of service or arbitrary code execution.
How do I fix CVE-2014-9379?
To fix CVE-2014-9379, upgrade to a version of Ettercap that addresses the vulnerability as provided by the project's maintainers.
What software is affected by CVE-2014-9379?
CVE-2014-9379 affects Ettercap version 0.8.1 specifically.
What type of vulnerability is CVE-2014-9379?
CVE-2014-9379 is a stack-based buffer overflow vulnerability.
Can CVE-2014-9379 lead to remote code execution?
Yes, CVE-2014-9379 can lead to remote code execution due to an incorrect cast in the radius_get_attribute function.