nmap: Multiple vulnerabilities (CVE-2017-18594, CVE-2018-15173)
CVE-2017-18594: denial of service condition due to a double free when SSH connection fails
A vulnerability was found in nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-18594
CVE-2018-15173: Stack exhausation when -sV option is used allows for DoS
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-15173
- http://code610.blogspot.com/2018/07/crashing-nmap-770.html
Affected branches:
-
master (3861e35f) -
3.10-stable -
3.9-stable -
3.8-stable -
3.7-stable
Edited by Kevin Daudt