Updated nmap packages fix security vulnerability:
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition
due to a double free when an SSH connection fails, as demonstrated by a
leading \n character to ssh-brute.nse or ssh-auth-methods.nse
(CVE-2017-18594).
Also, when a server forced a protocol and did not return TLS ALPN extension,
this caused an infinite loop.
- https://bugs.mageia.org/show_bug.cgi?id=25770
- https://github.com/nmap/nmap/commit/3b8b6516a7697d8b6d4cd87e253daa369fcdbf2a
- - https://www.cve.org/CVERecord?id=CVE-2017-18594
- 7/core/nmap-7.70-2.2.mga7
Get the latest Linux and open source security news straight to your inbox.