PT-2017-18293 · Ettercap · Ettercap

Agostino Sarubbo

·

Published

2017-04-30

·

Updated

2017-11-04

·

CVE-2017-8366

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ettercap version 0.8.2
Description The issue allows remote attackers to cause a denial of service, resulting in a heap-based buffer overflow and application crash, or possibly have other unspecified impacts. This is achieved by using a crafted filter that is mishandled by etterfilter.
Recommendations For Ettercap version 0.8.2, consider avoiding the use of crafted filters until a patch is available. As a temporary workaround, restrict the use of the strescape function in ec strings.c to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-8366
DSA-3874-1
MGASA-2017-0173

Affected Products

Ettercap