Input validation error in Ettercap - CVE-2014-9381
Published: December 19, 2014 / Updated: August 9, 2020
Ettercap
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c in Ettercap 0.8.1 allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation.