vendor:
Ettercap
by:
Ferm?n J. Serna
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Ettercap
Affected Version From: 0.6.3.1
Affected Version To: 0.6.3.1
Patch Exists: YES
Related CWE: N/A
CPE: a:ettercap:ettercap
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, BSD, Windows
2002
Ettercap Buffer Overflow Vulnerability
A remotely exploitable buffer overflow condition exists in Ettercap. If a large packet is recieved and passed to some decoders, stack data may be overwritten, leading to execution of arbitrary code. This condition may be caused by associating Ettercap with an interface with a larger MTU than ethernet, or by sending a forged packet with a misleading data length field.
Mitigation:
Upgrade to the latest version of Ettercap.