An unchecked sscanf() call in ettercap before 0.7.5 allows an insecure temporary settings file to overflow a static-sized buffer on the stack.
{
"binaries": [
{
"binary_name": "ettercap-common",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-common-dbgsym",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-dbg",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-graphical",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-graphical-dbgsym",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-text-only",
"binary_version": "1:0.8.0-11ubuntu0.3"
},
{
"binary_name": "ettercap-text-only-dbgsym",
"binary_version": "1:0.8.0-11ubuntu0.3"
}
],
"availability": "No subscription required"
}