CVE-2014-6396
EPSS 2.8%
Description
The dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted password length, which triggers a 0 character to be written to an arbitrary memory location.
How to fix CVE-2014-6396
To remediate CVE-2014-6396, upgrade the affected package to a fixed version below.
- Debian/ettercap—upgrade to 1:0.8.1-3 or later
Is CVE-2014-6396 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:0.8.1-3