VulnerabilityModified
CVE-2017-18594
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
HIGH 7.5EPSS 3.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 3.16% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-415
- Affected
- nmap/nmap
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00075.html
- https://github.com/AMatchandaHaystack/Research/blob/master/Nmap%26libsshDFThird Party Advisory
- https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9adPatch, Third Party Advisory
- https://github.com/nmap/nmap/issues/1077Patch, Third Party Advisory
- https://github.com/nmap/nmap/issues/1227Exploit, Third Party Advisory
- https://seclists.org/nmap-announce/2019/0Mailing List, Third Party Advisory
- https://seclists.org/nmap-dev/2018/q2/45Mailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00073.html
- http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00075.html
- https://github.com/AMatchandaHaystack/Research/blob/master/Nmap%26libsshDFThird Party Advisory
- https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9adPatch, Third Party Advisory
- https://github.com/nmap/nmap/issues/1077Patch, Third Party Advisory
- https://github.com/nmap/nmap/issues/1227Exploit, Third Party Advisory
- https://seclists.org/nmap-announce/2019/0Mailing List, Third Party Advisory
- https://seclists.org/nmap-dev/2018/q2/45Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.