CVE-2017-18594: Double Free
Published Aug 28, 2019
·Updated
nselibssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
Affected Software
1 affected component
Nmap Nmap=7.70
Remediation
Patch Available
Event History
Aug 28, 2019
CVE Published
via MITRE·11:50 PM
Data Sourced
via MITRE·11:50 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18594?
CVE-2017-18594 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-18594?
To fix CVE-2017-18594, you should upgrade to a version of Nmap later than 7.70.
3
What software is affected by CVE-2017-18594?
CVE-2017-18594 affects Nmap version 7.70.
4
What causes the denial of service in CVE-2017-18594?
The denial of service in CVE-2017-18594 is caused by a double free error when an SSH connection fails.
5
What is the impact of exploiting CVE-2017-18594?
Exploiting CVE-2017-18594 can lead to crashes in the Nmap application.