CVE-2014-6395
Ettercap 0.8.0 < 0.8.1 - Multiple Denial of Service Vulnerabilities
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.
Desbordamiento de búfer basado en memoria dinámica en la función dissector_postgresql en dissectors/ec_postgresql.c en Ettercap en versiones anteriores a 0.8.1 permite a atacantes remotos provocar una denegación de servicio o posiblemente ejecutar un código arbitrario a través de un valor de longitud de contraseña manipulado que es inconsistente con la longitud de contraseña actual.
Ettercap versions 0.8.0 and 0.8.1 suffers from multiple denial of service vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-09-15 CVE Reserved
- 2014-12-16 CVE Published
- 2014-12-19 First Exploit
- 2024-01-13 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/archive/1/534248/100/0/threaded | Mailing List | |
http://www.securityfocus.com/bid/71689 | Vdb Entry | |
https://github.com/Ettercap/ettercap/commit/e3abe7d7585ecc420a7cab73313216613aadad5a | X_refsource_confirm | |
https://www.obrela.com/home/security-labs/advisories/osi-advisory-osi-1402 | X_refsource_misc |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35580 | 2014-12-19 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/201505-01 | 2020-02-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ettercap-project Search vendor "Ettercap-project" | Ettercap Search vendor "Ettercap-project" for product "Ettercap" | <= 0.8.0 Search vendor "Ettercap-project" for product "Ettercap" and version " <= 0.8.0" | - |
Affected
|