First published: Wed Aug 28 2019(Updated: )
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
libpcap | =7.70 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18594 is classified as a denial of service vulnerability.
To fix CVE-2017-18594, you should upgrade to a version of Nmap later than 7.70.
CVE-2017-18594 affects Nmap version 7.70.
The denial of service in CVE-2017-18594 is caused by a double free error when an SSH connection fails.
Exploiting CVE-2017-18594 can lead to crashes in the Nmap application.