vendor:
Ettercap
by:
Sajjad Pourali
3.3
CVSS
LOW
Stack overflow
121
CWE
Product Name: Ettercap
Affected Version From: 0.7.4 and earlier
Affected Version To: 0.7.5.1
Patch Exists: YES
Related CWE: CVE-2012-0722
CPE: ettercap
Platforms Tested:
2012
Ettercap Stack overflow (CWE-121)
The Ettercap software version 0.7.5.1 and earlier is vulnerable to a stack overflow vulnerability, as identified by CWE-121. This vulnerability allows an attacker to execute arbitrary code or cause a denial of service (DoS) by sending a specially crafted input to the affected software. The vulnerability exists in the `ec_scan.c` file, specifically in the `fscanf` function call at line 633-635. By sending a maliciously crafted input, an attacker can trigger a stack overflow and potentially gain control over the affected system. This vulnerability has been assigned CVE-2012-0722.
Mitigation:
To mitigate this vulnerability, users are advised to apply the provided patch. The patch can be downloaded from the vendor's website at http://www.securation.com/files/2013/01/ec.patch.