An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2425-2 Rating: important References: #1135350 #1148742 Cross-References: CVE-2017-18594 CVE-2018-15173 Affected Products: SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2017-18594: Fixed a denial of service condition due to a double free when an SSH connection fails. (bsc#1148742) Non-security issue fixed: - Fixed a regression in the version scanner caused, by the fix for CVE-2018-15173. (bsc#1135350) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP2-2020-1874=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP1-2020-1874=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-1874=1 Package List: - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2 (aarch64 ppc64le s390x x86_64): nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 nping-7.70-3.12.1 nping-debuginfo-7.70-3.12.1 - SUSE Linux Enterprise Modulefor Packagehub Subpackages 15-SP1 (aarch64 ppc64le s390x x86_64): nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 nping-7.70-3.12.1 nping-debuginfo-7.70-3.12.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): nmap-7.70-3.12.1 nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 References: https://www.suse.com/security/cve/CVE-2017-18594.html https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1135350 https://bugzilla.suse.com/1148742 _______________________________________________ sle-security-updates mailing list
Updated nmap packages fix security vulnerability: nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse . MGASA-2020-0216 - Updated nmap packages fix security vulnerability Publication date: 24 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0216.html Type: security Affected Mageia releases: 7 CVE: CVE-2017-18594 Updated nmap packages fix security vulnerability: nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse (CVE-2017-18594). Also, when a server forced a protocol and did not return TLS ALPN extension, this caused an infinite loop. References: - https://bugs.mageia.org/show_bug.cgi?id=25770 - https://github.com/nmap/nmap/commit/3b8b6516a7697d8b6d4cd87e253daa369fcdbf2a - - https://www.cve.org/CVERecord?id=CVE-2017-18594 SRPMS: - 7/core/nmap-7.70-2.2.mga7 . A security patch for Nmap in Mageia addresses a denial of service vulnerability caused by improper handling of memory in SSH connection processes.. nmap security,vulnerability fix,Mageia updates,SSH security issues. . Severity: Critical. LinuxSecurity.com Team
Updated nmap packages fix security vulnerability: Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service (CVE-2018-15173). . MGASA-2019-0294 - Updated nmap packages fix security vulnerability Publication date: 16 Oct 2019 URL: https://advisories.mageia.org/MGASA-2019-0294.html Type: security Affected Mageia releases: 7 CVE: CVE-2018-15173 Updated nmap packages fix security vulnerability: Nmap through 7.70, when the -sV option is used, allows remote attackersto cause a denial of service (stack consumption and application crash) via a crafted TCP-based service (CVE-2018-15173). References: - https://bugs.mageia.org/show_bug.cgi?id=25262 - - https://www.cve.org/CVERecord?id=CVE-2018-15173 SRPMS: - 7/core/nmap-7.70-2.1.mga7 . Mageia 2021-0457 revisions secure libc libraries to address a segmentation fault issue triggered by malformed inputs.. nmap security, Mageia 2019-0294, denial of service, security update. . Severity: Medium. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2200-1 Rating: important References: #1135350 #1148742 Cross-References: CVE-2017-18594 CVE-2018-15173 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2017-18594: Fixed a denial of service condition due to a double free when an SSH connection fails. (bsc#1148742) Non-security issue fixed: - Fixed a regression in the version scanner caused, by the fix for CVE-2018-15173. (bsc#1135350) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2200=1 Package List: - openSUSE Leap 15.1 (x86_64): ncat-7.70-lp151.3.9.1 ncat-debuginfo-7.70-lp151.3.9.1 ndiff-7.70-lp151.3.9.1 nmap-7.70-lp151.3.9.1 nmap-debuginfo-7.70-lp151.3.9.1 nmap-debugsource-7.70-lp151.3.9.1 nping-7.70-lp151.3.9.1 nping-debuginfo-7.70-lp151.3.9.1 zenmap-7.70-lp151.3.9.1 References: https://www.suse.com/security/cve/CVE-2017-18594.html https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1135350 https://bugzilla.suse.com/1148742 -- . This release includes crucial improvements for nmap on openSUSE Leap 15.1, outlining the severity of the fixes and the specific issues that have been addressed.. openSUSE Update, nmap SecurityFix, Denial of Service, Software Patch. . Severity: Important. LinuxSecurity.com Team
An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2198-1 Rating: important References: #1135350 #1148742 Cross-References: CVE-2017-18594 CVE-2018-15173 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2017-18594: Fixed a denial of service condition due to a double free when an SSH connection fails. (bsc#1148742) Non-security issue fixed: - Fixed a regression in the version scanner caused, by the fix for CVE-2018-15173. (bsc#1135350) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-2198=1 Package List: - openSUSE Leap 15.0 (x86_64): ncat-7.70-lp150.2.9.1 ncat-debuginfo-7.70-lp150.2.9.1 ndiff-7.70-lp150.2.9.1 nmap-7.70-lp150.2.9.1 nmap-debuginfo-7.70-lp150.2.9.1 nmap-debugsource-7.70-lp150.2.9.1 nping-7.70-lp150.2.9.1 nping-debuginfo-7.70-lp150.2.9.1 zenmap-7.70-lp150.2.9.1 References: https://www.suse.com/security/cve/CVE-2017-18594.html https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1135350 https://bugzilla.suse.com/1148742 -- . Crucial patch released for openSUSE nmap, tackling denial of service vulnerabilities and several other high-severity concerns.. openSUSE nmap security update, nmap vulnerabilities, update fornmap issues. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2426-1 Rating: important References: #1135350 Cross-References: CVE-2018-15173 Affected Products: SUSE Linux Enterprise Server 12-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for nmap fixes the following issues: - Fixed a regression in the version scanner, caused by the fix for CVE-2018-15173. (bsc#1135350) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP4: zypper in -t patch SUSE-SLE-SERVER-12-SP4-2019-2426=1 Package List: - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): nmap-6.46-3.6.1 nmap-debuginfo-6.46-3.6.1 nmap-debugsource-6.46-3.6.1 References: https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1135350 _______________________________________________ sle-security-updates mailing list
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2425-1 Rating: important References: #1135350 #1148742 Cross-References: CVE-2017-18594 CVE-2018-15173 Affected Products: SUSE Linux Enterprise Module for Packagehub Subpackages 15 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2017-18594: Fixed a denial of service condition due to a double free when an SSH connection fails. (bsc#1148742) Non-security issue fixed: - Fixed a regression in the version scanner caused, by the fix for CVE-2018-15173. (bsc#1135350) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Packagehub Subpackages 15: zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-2019-2425=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-2425=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-2425=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -tpatch SUSE-SLE-Module-Basesystem-15-SP1-2019-2425=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-2425=1 Package List: - SUSE Linux Enterprise Module for Packagehub Subpackages 15 (aarch64 ppc64le s390x x86_64): nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 nping-7.70-3.12.1 nping-debuginfo-7.70-3.12.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): ncat-7.70-3.12.1 ncat-debuginfo-7.70-3.12.1 ndiff-7.70-3.12.1 nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 nping-7.70-3.12.1 nping-debuginfo-7.70-3.12.1 zenmap-7.70-3.12.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): ncat-7.70-3.12.1 ncat-debuginfo-7.70-3.12.1 ndiff-7.70-3.12.1 nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 nping-7.70-3.12.1 nping-debuginfo-7.70-3.12.1 zenmap-7.70-3.12.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): nmap-7.70-3.12.1 nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): nmap-7.70-3.12.1 nmap-debuginfo-7.70-3.12.1 nmap-debugsource-7.70-3.12.1 References: https://www.suse.com/security/cve/CVE-2017-18594.html https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1135350 https://bugzilla.suse.com/1148742 _______________________________________________ sle-security-updates mailing list
An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for nmap ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1290-2 Rating: moderate References: #1104139 #1133512 Cross-References: CVE-2018-15173 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for nmap fixes the following issues: Security issue fixed: - CVE-2018-15173: Fixed a remote denial of service attack via a crafted TCP-based service (bsc#1104139). Non-security issue fixed: - Add missing runtime dependency python-xml which prevented zenmap from starting (bsc#1133512). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-1290=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-1290=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): ncat-7.70-3.5.1 ncat-debuginfo-7.70-3.5.1 ndiff-7.70-3.5.1 nmap-debuginfo-7.70-3.5.1 nmap-debugsource-7.70-3.5.1 nping-7.70-3.5.1 nping-debuginfo-7.70-3.5.1 zenmap-7.70-3.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): nmap-7.70-3.5.1 nmap-debuginfo-7.70-3.5.1 nmap-debugsource-7.70-3.5.1 References: https://www.suse.com/security/cve/CVE-2018-15173.html https://bugzilla.suse.com/1104139 https://bugzilla.suse.com/1133512 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.