Back

HIGH

nmap: denial of service condition due to a double free when SSH connection fails

Published Aug 28, 2019

Description

nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.

Affected products

Remediation

Red Hat statement

Red Hat Enterprise Linux 8 is shipped with a vulnerable version of nmap sources, however, the libssh2 module is explicitly excluded from compilation, and is thus not affected. A future update may fix the source. Red Hat Enterprise Linux 7 and older are shipped with nmap-6.40 and older, which do not contain the libssh2 module.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 28, 2019
Updated Aug 5, 2024
Reserved Aug 28, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Aug 10, 2019