Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux ASA-201503-12 High: Ettercap Code Execution Threats

The package ettercap before version 0.8.2-1 is vulnerable to multiple issues including but not limited to arbitrary code execution, arbitrary memory write and denial of service. . Arch Linux Security Advisory ASA-201503-12 ========================================= Severity: High Date : 2015-03-17 CVE-ID : CVE-2014-6395 CVE-2014-6396 CVE-2014-9376 CVE-2014-9377 CVE-2014-9378 CVE-2014-9379 CVE-2014-9380 CVE-2014-9381 Package : ettercap Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package ettercap before version 0.8.2-1 is vulnerable to multiple issues including but not limited to arbitrary code execution, arbitrary memory write and denial of service. Resolution ========= Upgrade to 0.8.2-1. # pacman -Syu "ettercap> =0.8.2-1" The problems have been fixed upstream in version 0.8.2. Workaround ========= None. Description ========== - CVE-2014-6395 (arbitrary code execution) Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password. - CVE-2014-6396 (arbitrary memory write) The dissector_postgresql function in dissectors/ec_postgresql.c allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted password length, which triggers a 0 character to be written to an arbitrary memory location. - CVE-2014-9376 (arbitrary code execution) Integer underflow allows remote attackers to cause a denial of service (out-of-bounds write) and possibly execute arbitrary code via a small (1) size variable value in the dissector_dhcp function in dissectors/ec_dhcp.c, (2) length value to the dissector_gg function in dissectors/ec_gg.c, or (3) string length to the get_decode_len function in ec_utils.c or a request without a (4) username or (5)password to the dissector_TN3270 function in dissectors/ec_TN3270.c. - CVE-2014-9377 (arbitrary code execution) Heap-based buffer overflow in the nbns_spoof function in plug-ins/nbns_spoof/nbns_spoof.c allows remote attackers to cause a denial of service or possibly execute arbitrary code via a large netbios packet. - CVE-2014-9378 (arbitrary code execution) Ettercap does not validate certain return values, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted (1) name to the parse_line function in mdns_spoof/mdns_spoof.c or (2) base64 encoded password to the dissector_imap function in dissectors/ec_imap.c. - CVE-2014-9379 (arbitrary code execution) The radius_get_attribute function in dissectors/ec_radius.c performs an incorrect cast, which allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via unspecified vectors, which triggers a stack-based buffer overflow. - CVE-2014-9380 (denial of service) The dissector_cvs function in dissectors/ec_cvs.c allows remote attackers to cause a denial of service (out-of-bounds read) via a packet containing only a CVS_LOGIN signature. - CVE-2014-9381 (denial of service) Integer signedness error in the dissector_cvs function in dissectors/ec_cvs.c allows remote attackers to cause a denial of service (crash) via a crafted password, which triggers a large memory allocation. Impact ===== A remote attacker is able to send specially crafted packets to perform arbitrary code execution, arbitrary memory write or denial of service via variousvectors. References ========= https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6395 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-6396 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9376 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9377 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9378 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9379 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9380 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9381 https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-9395 https://bugs.archlinux.org/task/44174 . Arch Linux Security Update ASA-202303-01 tackles critical vulnerabilities in ettercap, offering several crucial patches. Users are strongly encouraged to upgrade without delay.. Arch Linux, Ettercap, High Severity Issues, Multiple Fixes, Remote Code Execution. . LinuxSecurity.com Team

Calendar 2 Mar 17, 2015 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here