Junglewise Threat Intelligence

CVE-2026-9365: Ettercap heap buffer overflow in GG Dissector

CVE-2026-9365 · Severity: medium · CVSS 5.6 · Published 2026-05-24

Executive brief

Ettercap, a network security tool used for traffic analysis and auditing, contains a memory handling vulnerability in its Gadu-Gadu (GG) protocol dissector. An attacker can exploit this by sending specially crafted network traffic, potentially causing the application to crash or allowing for unauthorized code execution. This could disrupt network monitoring operations or compromise the system running the tool.

Technical details

A heap-based buffer overflow exists in the FUNC_DECODER function within src/dissectors/ec_gg.c of Ettercap. The vulnerability is caused by improper bounds checking when copying attacker-controlled data from the Gadu-Gadu (GG) protocol into a fixed-size heap buffer (tbuf2, 71 bytes). Specifically, the code uses strncpy with a length derived from the gg->len field without verifying it against the destination buffer's size. An attacker can trigger this remotely by sending crafted TCP traffic on port 8074. While the attack complexity is high due to heap layout dependencies, it can lead to memory corruption or a crash. The issue is fixed in version 0.8.4 by implementing bounded copies and strict length validation.

Affected products

  • Ettercap Project Ettercap up to 0.8.3

Timeline

  • 2026-04-20: disclosed: Issue reported on GitHub by user dapickle
  • 2026-04-27: patched: Fix merged into master branch
  • 2026-05-24: advisory: CVE-2026-9365 published

References