Описание
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.
A flaw was found in Nmap. A remote attacker can exploit this denial of service vulnerability by sending a specially crafted packet that includes a zero-length Transmission Control Protocol (TCP) option. This malformed packet forces the application to enter an infinite loop during packet processing, consuming excessive memory and ultimately causing the Nmap application to crash.
Отчет
Moderate: This denial of service vulnerability in Nmap allows a remote attacker to crash the application by sending a specially crafted TCP packet. The impact is limited to the availability of the Nmap process itself, typically affecting active network scanning operations rather than persistent services.
Меры по смягчению последствий
To mitigate this issue, avoid running Nmap with Network Scripting Engine (NSE) scripts that perform raw packet dissection against untrusted or potentially malicious network targets. This vulnerability is triggered by specially crafted TCP packets when Nmap is actively scanning with such scripts. If Nmap is not required, consider uninstalling the nmap package to eliminate the risk.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | nmap | Fix deferred | ||
| Red Hat Enterprise Linux 6 | nmap | Out of support scope | ||
| Red Hat Enterprise Linux 7 | nmap | Fix deferred | ||
| Red Hat Enterprise Linux 8 | nmap | Fix deferred | ||
| Red Hat Enterprise Linux 9 | nmap | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.
Nmap 7.99 Denial of Service via Zero-Length TCP Option Packet
Nmap versions up to and including 7.99 contains a denial of service vu ...
Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a crafted packet containing a zero-length TCP option. The malformed packet forces the Packet:parse_options() function in nselib/packet.lua to allocate objects in an infinite loop, causing an out-of-memory condition that results in application crash.
EPSS
6.5 Medium
CVSS3