Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Locutusofborg

#18063of 53,624
15Total CVSS
Vulnerabilities · 2
High
2
PT-2014-7208
7.5
2014-12-19
Ettercap · Ettercap · CVE-2014-6395
**Name of the Vulnerable Software and Affected Versions** Ettercap versions prior to 0.8.1 **Description** The issue is related to a heap-based buffer overflow in the `dissector postgresql` function, which can be triggered by remote attackers sending a crafted password length value that does not match the actual length of the password. This can lead to a denial of service or potentially allow the execution of arbitrary code. **Recommendations** For versions prior to 0.8.1, update to version 0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the `dissector postgresql` function until a patch is available.
PT-2014-7209
7.5
2014-12-19
Ettercap · Ettercap · CVE-2014-6396
**Name of the Vulnerable Software and Affected Versions** Ettercap versions prior to 0.8.1 **Description** The issue allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted password length. This is triggered by writing a 0 character to an arbitrary memory location in the dissector postgresql function. **Recommendations** For versions prior to 0.8.1, update to version 0.8.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the dissector postgresql function until a patch is available.