First published: Fri Dec 19 2014(Updated: )
Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ettercap | =0.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9381 has a medium severity rating as it leads to a denial of service through a crash caused by a crafted password.
To fix CVE-2014-9381, upgrade Ettercap to version 0.8.2 or later, which addresses this vulnerability.
The potential impact of CVE-2014-9381 includes service disruption due to crashes in Ettercap when exploited.
Users of Ettercap version 0.8.1 are specifically affected by CVE-2014-9381.
CVE-2014-9381 targets systems running Ettercap version 0.8.1 regardless of operating system.