FS#44174 - [ettercap][CVE-2014-9380][CVE-2014-9381]

Attached to Project: Community Packages
Opened by Christian Rebischke (Shibumi) - Friday, 13 March 2015, 15:22 GMT
Last edited by Daniel Micay (thestinger) - Tuesday, 17 March 2015, 00:19 GMT
Task Type Bug Report
Category Packages
Status Closed
Assigned To Jelle van der Waa (jelly)
Daniel Micay (thestinger)
Architecture All
Severity High
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Summary
=======

CVE-2014-9380
-------------
The dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (out-of-bounds read) via a packet containing only a CVS_LOGIN signature.

CVE-2014-9381
-------------
Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.

References
==========
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9380
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9381
https://www.obrela.com/home/security-labs/advisories/osi-advisory-osi-1402/
This task depends upon

Closed by  Daniel Micay (thestinger)
Tuesday, 17 March 2015, 00:19 GMT
Reason for closing:  Fixed
Comment by Daniel Micay (thestinger) - Saturday, 14 March 2015, 06:21 GMT
There are a lot of silent security fixes in master with no CVE assigned too... it's not really a well-maintained project and the best option might be dropping it to the AUR. You'd expect a release after dozens of security fixes *in a security-based project no less* but no...
Comment by Levente Polyak (anthraxx) - Tuesday, 17 March 2015, 00:06 GMT
This ticket is now resolved:
update 0.8.2-1 available in [community] fixes all provided issues in this ticket (including all those noted in the advisory but not here).
ASA-201503-12 and ASA-201503-13 are already published to notify about those issues.

Loading...