HIGH
Ettercap 0.8.1 does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in dissectors/ec_imap.c
Published Dec 19, 2014
7.5
HIGHCVSS 2.0
EPSS 3.91%
Description
Affected products
Remediation
Metrics
References (6)
Change history (0)
No recorded changes yet.