FS#44174 - [ettercap][CVE-2014-9380][CVE-2014-9381]
Attached to Project:
Community Packages
Opened by Christian Rebischke (Shibumi) - Friday, 13 March 2015, 15:22 GMT
Last edited by Daniel Micay (thestinger) - Tuesday, 17 March 2015, 00:19 GMT
Opened by Christian Rebischke (Shibumi) - Friday, 13 March 2015, 15:22 GMT
Last edited by Daniel Micay (thestinger) - Tuesday, 17 March 2015, 00:19 GMT
|
Details
Summary
======= CVE-2014-9380 ------------- The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a packet containing only a CVS_LOGIN signature. CVE-2014-9381 ------------- Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation. References ========== https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9380 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9381 https://www.obrela.com/home/security-labs/advisories/osi-advisory-osi-1402/ |
This task depends upon
update 0.8.2-1 available in [community] fixes all provided issues in this ticket (including all those noted in the advisory but not here).
ASA-201503-12 and ASA-201503-13 are already published to notify about those issues.