Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Mandriva: 2020-0216 Critical: Nmap Denial of Service Vulnerability

mageia
Calendar Grey May 24, 2020
Dist Mageia Esm H88
A security patch for Nmap in Mageia addresses a denial of service vulnerability caused by improper handling of memory in SSH connection processes.
Updated nmap packages fix security vulnerability: nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as dem...

Summary

Updated nmap packages fix security vulnerability:
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse (CVE-2017-18594).
Also, when a server forced a protocol and did not return TLS ALPN extension, this caused an infinite loop.

References

- https://bugs.mageia.org/show_bug.cgi?id=25770

- https://github.com/nmap/nmap/commit/3b8b6516a7697d8b6d4cd87e253daa369fcdbf2a

- - https://www.cve.org/CVERecord?id=CVE-2017-18594

Resolution

SRPMS

- 7/core/nmap-7.70-2.2.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 May 2020
URL: https://advisories.mageia.org/MGASA-2020-0216.html
Type: security
CVE: CVE-2017-18594

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here