Candidate: CVE-2013-0722 PublicDate: 2013-01-11 22:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0722 http://www.openwall.com/lists/oss-security/2013/01/10/2 http://www.exploit-db.com/exploits/23945/ https://secunia.com/advisories/51731/ https://bugzilla.redhat.com/show_bug.cgi?id=894092 https://bugs.gentoo.org/show_bug.cgi?id=451198 http://www.securation.com/files/2013/01/ec.patch http://secunia.com/advisories/51731 Description: Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=697987 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_ettercap: upstream_ettercap: released (1:0.7.5.1-2) hardy_ettercap: ignored (reached end-of-life) lucid_ettercap: ignored (reached end-of-life) oneiric_ettercap: ignored (reached end-of-life) precise_ettercap: ignored (reached end-of-life) precise/esm_ettercap: DNE (precise was needed) quantal_ettercap: ignored (reached end-of-life) raring_ettercap: ignored (reached end-of-life) saucy_ettercap: ignored (reached end-of-life) trusty_ettercap: not-affected (1:0.8.0-11) trusty/esm_ettercap: DNE (trusty was not-affected [1:0.8.0-11]) utopic_ettercap: ignored (reached end-of-life) vivid_ettercap: ignored (reached end-of-life) vivid/stable-phone-overlay_ettercap: DNE vivid/ubuntu-core_ettercap: DNE wily_ettercap: ignored (reached end-of-life) xenial_ettercap: not-affected (1:0.8.2-2build1) yakkety_ettercap: not-affected (1:0.8.2-2build1) zesty_ettercap: not-affected devel_ettercap: not-affected