Описание
Security update for nmap
This update for nmap fixes the following issues:
Security issue fixed:
- CVE-2017-18594: Fixed a denial of service condition due to a double free when an SSH connection fails. (bsc#1148742)
Non-security issue fixed:
- Fixed a regression in the version scanner caused, by the fix for CVE-2018-15173. (bsc#1135350)
Список пакетов
SUSE Linux Enterprise Module for Basesystem 15
nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Package Hub 15
nping-7.70-3.12.1
Ссылки
- Link for SUSE-SU-2019:2425-1
- E-Mail link for SUSE-SU-2019:2425-1
- SUSE Security Ratings
- SUSE Bug 1135350
- SUSE Bug 1148742
- SUSE CVE CVE-2017-18594 page
- SUSE CVE CVE-2018-15173 page
Описание
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP1:nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Basesystem 15:nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Package Hub 15:nping-7.70-3.12.1
Ссылки
- CVE-2017-18594
- SUSE Bug 1148742
Описание
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP1:nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Basesystem 15:nmap-7.70-3.12.1
SUSE Linux Enterprise Module for Package Hub 15:nping-7.70-3.12.1
Ссылки
- CVE-2018-15173
- SUSE Bug 1104139