Source: ettercap
X-Debbugs-CC: [email protected]
Severity: grave
Tags: security

Hi,

The following vulnerability was published for ettercap.

CVE-2026-9365[0]:
| A vulnerability has been found in Ettercap up to 0.8.3. The affected
| element is the function FUNC_DECODER of the file
| src/dissectors/ec_gg.c of the component GG Dissector. The
| manipulation of the argument gg leads to heap-based buffer overflow.
| The attack is possible to be carried out remotely. The complexity of
| an attack is rather high. The exploitability is described as
| difficult. The exploit has been disclosed to the public and may be
| used. Upgrading to version 0.8.4 is sufficient to fix this issue.
| The identifier of the patch is
| feeae6fa366e01a3dd9f1857ec6aae847b2ae00c. It is suggested to upgrade
| the affected component.

https://github.com/Ettercap/ettercap/issues/1306
https://github.com/Ettercap/ettercap/pull/1307
https://github.com/Ettercap/ettercap/commit/feeae6fa366e01a3dd9f1857ec6aae847b2ae00c


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-9365
    https://www.cve.org/CVERecord?id=CVE-2026-9365

Please adjust the affected versions in the BTS as needed.

Reply via email to