High severity7.5NVD Advisory· Published Aug 29, 2019· Updated Jun 17, 2026
CVE-2017-18594
CVE-2017-18594
Description
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- Nmap/Nmapdescription
- osv-coords9 versionspkg:rpm/opensuse/nmap&distro=openSUSE%20Leap%2015.0pkg:rpm/opensuse/nmap&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/nmap&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015pkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015pkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1pkg:rpm/suse/nmap&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2
< 7.70-lp150.2.9.1+ 8 more
- (no CPE)range: < 7.70-lp150.2.9.1
- (no CPE)range: < 7.70-lp151.3.9.1
- (no CPE)range: < 7.92-4.1
- (no CPE)range: < 7.70-3.12.1
- (no CPE)range: < 7.70-3.12.1
- (no CPE)range: < 7.70-3.12.1
- (no CPE)range: < 7.70-3.12.1
- (no CPE)range: < 7.70-3.12.1
- (no CPE)range: < 7.70-3.12.1
Patches
Vulnerability mechanics
References
8- github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9adnvdPatchThird Party Advisory
- github.com/nmap/nmap/issues/1077nvdPatchThird Party Advisory
- github.com/nmap/nmap/issues/1227nvdExploitThird Party Advisory
- github.com/AMatchandaHaystack/Research/blob/master/Nmap%26libsshDFnvdThird Party Advisory
- seclists.org/nmap-announce/2019/0nvdMailing ListThird Party Advisory
- seclists.org/nmap-dev/2018/q2/45nvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00073.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2019-09/msg00075.htmlnvd
News mentions
0No linked articles in our index yet.