VDB
CVE-2026-3606
CVE-2026-3606
PUBLISHED
CVSS 4.800000190734863 MEDIUM
A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
EPSS 0.03% · 8.3th percentile
Risk Scores
CVSS 4.0
4.800000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
EPSS Score
0.03%
8.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Ettercap | 0.8.4-Garofalo, 0.8.4-Garofalo, 0.8.4-Garofalo |
| ettercap-project | ettercap | 0.8.4, 0.8.4, 0.8.4 |
Timeline
- Mar 5, 2026 CVE ID Reserved
- Mar 5, 2026 CVE Published
- Mar 6, 2026 EPSS Score
- Mar 6, 2026 PoC Published
- Mar 6, 2026 PoC Published
- Mar 7, 2026 EPSS Score
- Mar 8, 2026 EPSS Score
- Mar 9, 2026 CVE Updated
- Mar 10, 2026 EPSS Score
- Mar 11, 2026 EPSS Score
- Mar 12, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
References
- VDB-349218 | Ettercap etterfilter ef_output.c add_data_segment out-of-bounds vdb
- VDB-349218 | CTI Indicators (IOB, IOC, IOA) url
- Submit #764648 | Ettercap ettercap Ettercap v0.8.4-Garofalo and master-branch Heap-based Buffer Overflow third-party-advisory
- https://github.com/Ettercap/ettercap/issues/1297 issue
- https://github.com/oneafter/0202/blob/main/et/repro exploit
- https://github.com/Ettercap/ettercap/ url
- https://nvd.nist.gov/vuln/detail/CVE-2026-3606 advisory
- https://github.com/Ettercap/ettercap url