CVE-2014-6395

Ettercap < 0.8.0 - Heap-Based Buffer Overflow via PostgreSQL Password Length

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-6395. PoCs published by Nick Sampanis.

AI-analyzed exploit summary This exploit demonstrates multiple denial-of-service (DoS) vulnerabilities in Ettercap versions 8.0-8.1 by crafting malformed packets for various protocols (NBNS, GG, DHCP, MDNS, PostgreSQL, RADIUS). It leverages the PacketFu library to generate and send these packets to trigger crashes or resource exhaustion.

Description

Heap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted password length value that is inconsistent with the actual length of the password.

Exploits (1)

exploitdb WORKING POC
by Nick Sampanis · rubydoslinux
https://www.exploit-db.com/exploits/35580

This exploit demonstrates multiple denial-of-service (DoS) vulnerabilities in Ettercap versions 8.0-8.1 by crafting malformed packets for various protocols (NBNS, GG, DHCP, MDNS, PostgreSQL, RADIUS). It leverages the PacketFu library to generate and send these packets to trigger crashes or resource exhaustion.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Ettercap 8.0-8.1
No auth needed
Prerequisites: PacketFu and pcaprub libraries installed · Network access to target · Valid MAC address for the interface
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/201505-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71689
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534248/100/0/threaded

Scores

EPSS 0.1306
EPSS Percentile 95.8%

Details

CWE
CWE-119
Status published
Products (1)
ettercap-project/ettercap < 0.8.0
Published Dec 19, 2014
Tracked Since Feb 18, 2026