SB2019102509 - Double Free in nmap (Alpine package)
Published: October 25, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Double Free (CVE-ID: CVE-2017-18594)
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary error when processing failed SSH connections in nse_libssh2.cc script in nmap. A remote attacker can trigger a double free error and perform a denial of service attack against the port scanner during scan process.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=c6bb37d9b3b97ad919485aa1bdc99206d3f41a5b
- https://git.alpinelinux.org/aports/commit/?id=84ef17ea9337f2176dcaa62288903906ef70a035
- https://git.alpinelinux.org/aports/commit/?id=2c2f9f27c8ac931989d3a5975e6f7356494150f0
- https://git.alpinelinux.org/aports/commit/?id=43fb559906f0919b32280ff71a52a535f7158e3c
- https://git.alpinelinux.org/aports/commit/?id=ddbe1950281feebd3fb30c7057104c724577c6a8