Ettercap GTK Insecure Temporary File Creation and Format String Vulnerabilities
BID:44078
Info
Ettercap GTK Insecure Temporary File Creation and Format String Vulnerabilities
| Bugtraq ID: | 44078 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-3843 CVE-2010-3844 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Oct 13 2010 12:00AM |
| Updated: | Apr 13 2015 09:33PM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 Gentoo Linux Ettercap Ettercap GTK 0 |
| Not Vulnerable: | |
Discussion
Ettercap GTK Insecure Temporary File Creation and Format String Vulnerabilities
Ettercap GTK is prone to an insecure-temporary-file-creation vulnerability and a remote format-string vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Exploiting the format-string issue will allow an attacker to execute arbitrary code in the context of the application, or cause denial-of-service conditions.
Ettercap GTK is prone to an insecure-temporary-file-creation vulnerability and a remote format-string vulnerability.
Successfully exploiting the temporary-file-creation issue allows an attacker to overwrite arbitrary files and to perform symbolic-link attacks in the context of the affected application. Other attacks may also be possible.
Exploiting the format-string issue will allow an attacker to execute arbitrary code in the context of the application, or cause denial-of-service conditions.
References
Ettercap GTK Insecure Temporary File Creation and Format String Vulnerabilities
References:
References:
- CVE request: ettercap GTK (Dan Rosenberg)
- Product Page (Ettercap)