FIx for CVE-2017-8366. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-8722576148 2017-06-15 02:57:02.424849 --------------------------------------------------------------------------------Name : ettercap Product : Fedora 25 Version : 0.8.2 Release : 4.2.fc25 URL : Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. --------------------------------------------------------------------------------Update Information: FIx for CVE-2017-8366 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447318 - CVE-2017-8366 ettercap: Heap-based buffer overflow in strescape function in ec_strings.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
FIx for CVE-2017-8366. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-36c7e7ef06 2017-06-15 02:56:58.020983 --------------------------------------------------------------------------------Name : ettercap Product : Fedora 24 Version : 0.8.2 Release : 4.2.fc24 URL : https://www.ettercap-project.org/ Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. --------------------------------------------------------------------------------Update Information: FIx for CVE-2017-8366 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447318 - CVE-2017-8366 ettercap: Heap-based buffer overflow in strescape function in ec_strings.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3874-1
Fix for CVE-2017-6430. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-06365bdcfd 2017-03-14 12:25:18.834506 -------------------------------------------------------------------------------- Name : ettercap Product : Fedora 25 Version : 0.8.2 Release : 4.1.fc25 URL : https://www.ettercap-project.org/ Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2017-6430 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1429571 - CVE-2017-6430 ettercap: Out-of-bounds read in etterfilter utility https://bugzilla.redhat.com/show_bug.cgi?id=1429571 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities have been found in Ettercap, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201505-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ettercap: Multiple vulnerabilities Date: May 13, 2015 Bugs: #532764 ID: 201505-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Ettercap, the worst of which allows remote attackers to execute arbitrary code. Background ========= Ettercap is a comprehensive suite for man in the middle attacks. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/ettercap < 0.8.2 > = 0.8.2 Description ========== Multiple vulnerabilities have been discovered in Ettercap. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Ettercap users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/ettercap-0.8.2" References ========= [ 1 ] CVE-2014-6395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6395 [ 2 ] CVE-2014-6396 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6396 [ 3 ] CVE-2014-9376 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9376 [ 4 ] CVE-2014-9377 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9377 [ 5 ] CVE-2014-9378 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9378 [ 6 ] CVE-2014-9379 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9379 [ 7 ] CVE-2014-9380 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9380 [ 8 ] CVE-2014-9381 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9381 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201505-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Multiple vulnerabilities have been found in Ettercap, the worst of which may allow execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ettercap: Multiple vulnerabilities Date: May 17, 2014 Bugs: #340897, #451198 ID: 201405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Ettercap, the worst of which may allow execution of arbitrary code. Background ========= Ettercap is a suite of tools for content filtering, sniffing and man in the middle attacks on a LAN. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/ettercap < 0.7.5.2 > = 0.7.5.2 Description ========== Multiple vulnerabilities have been discovered in Ettercap: * Ettercap does not handle temporary files securely (CVE-2010-3843). * A format string flaw in Ettercap could cause a buffer overflow (CVE-2010-3844). * A stack-based buffer overflow exists in Ettercap (CVE-2013-0722). Impact ===== A remote attacker could entice a user to load a specially crafted configuration file using Ettercap, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Ettercap usersshould upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/ettercap-0.7.5.2" References ========= [ 1 ] CVE-2010-3843 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3843 [ 2 ] CVE-2010-3844 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3844 [ 3 ] CVE-2013-0722 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0722 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
A vulnerability was discovered in the ettercap package which could allow a remote attacker to execute arbitrary code on the system running ettercap.. - ------------------------------------------------------------------------Debian Security Advisory DSA 749-1
Get the latest Linux and open source security news straight to your inbox.