Ettercap Remote Format String Vulnerability
BID:13820
Info
Ettercap Remote Format String Vulnerability
| Bugtraq ID: | 13820 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1796 |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2005 12:00AM |
| Updated: | Jul 12 2009 02:56PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ettercap Ettercap NG 0.7.2 Ettercap Ettercap NG 0.7.1 Ettercap Ettercap NG 0.7 .0 Ettercap Ettercap 0.6.9 Ettercap Ettercap 0.6.7 Ettercap Ettercap 0.6.6 .6 Ettercap Ettercap 0.6.5 Ettercap Ettercap 0.6.4 Ettercap Ettercap 0.6.3 .1 Ettercap Ettercap 0.6 .b Ettercap Ettercap 0.6 .a |
| Not Vulnerable: |
Ettercap Ettercap NG 0.7.3 |
Discussion
Ettercap Remote Format String Vulnerability
Ettercap is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to utilizing it as a format specifier in a formatted printing function.
To exploit this vulnerability, an attacker would craft network data that will result in one of the protocol dissectors logging usernames and passwords. Other means of attack may also be possible.
This vulnerability allows remote attackers to modify arbitrary memory locations, resulting in the control of program execution, leading to the ability to execute arbitrary machine code in the context of the affected application.
This vulnerability is only exploitable when the curses user interface is being utilized by a user.
Ettercap is susceptible to a remote format string vulnerability. This issue is due to a failure of the application to properly sanitize user-supplied input prior to utilizing it as a format specifier in a formatted printing function.
To exploit this vulnerability, an attacker would craft network data that will result in one of the protocol dissectors logging usernames and passwords. Other means of attack may also be possible.
This vulnerability allows remote attackers to modify arbitrary memory locations, resulting in the control of program execution, leading to the ability to execute arbitrary machine code in the context of the affected application.
This vulnerability is only exploitable when the curses user interface is being utilized by a user.
Exploit / POC
Ettercap Remote Format String Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Ettercap Remote Format String Vulnerability
Solution:
Gentoo users can upgrade by issuing the following commands:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/ettercap-0.7.3"
The vendor has released version 0.7.3 of Ettercap to address this issue.
Debian Linux has relased security advisory DSA 749-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Ettercap Ettercap 0.6 .b
Ettercap Ettercap 0.6 .a
Ettercap Ettercap 0.6.3 .1
Ettercap Ettercap 0.6.4
Ettercap Ettercap 0.6.5
Ettercap Ettercap 0.6.6 .6
Ettercap Ettercap 0.6.7
Ettercap Ettercap 0.6.9
Ettercap Ettercap NG 0.7 .0
Ettercap Ettercap NG 0.7.1
Ettercap Ettercap NG 0.7.2
Solution:
Gentoo users can upgrade by issuing the following commands:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-analyzer/ettercap-0.7.3"
The vendor has released version 0.7.3 of Ettercap to address this issue.
Debian Linux has relased security advisory DSA 749-1 addressing this issue. Please see the referenced advisory for details on obtaining and applying the appropriate updates.
Debian has released security advisory DSA 773-1 addressing several issues for their AMD64 port of the operating system. Please see the referenced advisory for further information.
Ettercap Ettercap 0.6 .b
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6 .a
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.3 .1
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.4
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.5
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.6 .6
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.7
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap 0.6.9
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap NG 0.7 .0
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap NG 0.7.1
-
Debian ettercap-common_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap-commo n_0.7.1-1sarge1_amd64.deb -
Debian ettercap-gtk_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap-gtk_0 .7.1-1sarge1_amd64.deb -
Debian ettercap_0.7.1-1sarge1_amd64.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/e/ettercap/ettercap_0.7.1 -1sarge1_amd64.deb -
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload
Ettercap Ettercap NG 0.7.2
-
Ettercap ettercap-NG-0.7.3.tar.gz
http://prdownloads.sourceforge.net/ettercap/ettercap-NG-0.7.3.tar.gz?d ownload