CVE-2017-18594
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading
character to ssh-brute.nse or ssh-auth-methods.nse.
nse_libssh2.cc en Nmap 7.70 está sujeto a una condición de denegación de servicio debido a una doble liberación cuando se produce un error en una conexión SSH, como lo demuestra un carácter principal de .n a ssh-brute.nse o ssh-auth-methods.nse.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-08-28 CVE Reserved
- 2019-08-28 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-21 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-415: Double Free
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
https://github.com/AMatchandaHaystack/Research/blob/master/Nmap%26libsshDF | Third Party Advisory | |
https://seclists.org/nmap-announce/2019/0 | Mailing List | |
https://seclists.org/nmap-dev/2018/q2/45 | Mailing List |
URL | Date | SRC |
---|---|---|
https://github.com/nmap/nmap/issues/1227 | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9ad | 2019-09-26 | |
https://github.com/nmap/nmap/issues/1077 | 2019-09-26 |