A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read.
Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Attack Parameters
Attack Vector
Local
Нужен локальный доступ
Attack Complexity
Low
Легко эксплуатировать
Attack Requirements
None
Нет дополнительных условий
Privileges Required
Low
Нужны базовые права
User Interaction
None
Не нужно действие пользователя
Impact Assessment
Confidentiality
None
Нет утечки данных
Integrity
None
Нет модификации данных
Availability
Low
Частичное нарушение работы
CVSS Vector v4.0
Weakness Type (CWE)
References 6
https://github.com/Ettercap/ettercap/
cna@vuldb.com
https://github.com/Ettercap/ettercap/issues/1297
cna@vuldb.com
https://github.com/oneafter/0202/blob/main/et/repro
cna@vuldb.com
https://vuldb.com/?ctiid.349218
cna@vuldb.com
https://vuldb.com/?id.349218
cna@vuldb.com
https://vuldb.com/?submit.764648
cna@vuldb.com