CVE-2014-9379
EPSS 2.8%
Description
The radius_get_attribute function in dissectors/ec_radius.c in Ettercap 0.8.1 performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow.
How to fix CVE-2014-9379
To remediate CVE-2014-9379, upgrade the affected package to a fixed version below.
- Debian/ettercap—upgrade to 1:0.8.1-3 or later
Is CVE-2014-9379 being exploited?
Low — EPSS is 2.8%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1:0.8.1-3