CVE-2014-9381: Medium severity ettercap vulnerability
Published Dec 19, 2014
·Updated
Integer signedness error in the dissectorcvs function in dissectors/eccvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.
Affected Software
1 affected component
Ettercap-project Ettercap=0.8.1
Remediation
Patch Available
Event History
Dec 19, 2014
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9381?
CVE-2014-9381 has a medium severity rating as it leads to a denial of service through a crash caused by a crafted password.
2
How do I fix CVE-2014-9381?
To fix CVE-2014-9381, upgrade Ettercap to version 0.8.2 or later, which addresses this vulnerability.
3
What are the potential impacts of CVE-2014-9381?
The potential impact of CVE-2014-9381 includes service disruption due to crashes in Ettercap when exploited.
4
Who is affected by CVE-2014-9381?
Users of Ettercap version 0.8.1 are specifically affected by CVE-2014-9381.
5
Is CVE-2014-9381 targeted at specific systems?
CVE-2014-9381 targets systems running Ettercap version 0.8.1 regardless of operating system.