{"id":"CVE-2017-18594","details":"nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \\n character to ssh-brute.nse or ssh-auth-methods.nse.","modified":"2026-08-07T14:49:09.788497Z","published":"2019-08-29T00:15:10.467Z","related":["SUSE-SU-2019:2425-1","SUSE-SU-2019:2425-2","openSUSE-SU-2019:2198-1","openSUSE-SU-2019:2200-1","openSUSE-SU-2024:11750-1"],"database_specific":{"unresolved_ranges":[{"vendor_product":"nmap:nmap","cpes":["cpe:2.3:a:nmap:nmap:7.70:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.70"},{"last_affected":"7.70"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00073.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00075.html"},{"type":"ADVISORY","url":"https://github.com/AMatchandaHaystack/Research/blob/master/Nmap%26libsshDF"},{"type":"ADVISORY","url":"https://seclists.org/nmap-announce/2019/0"},{"type":"ADVISORY","url":"https://seclists.org/nmap-dev/2018/q2/45"},{"type":"FIX","url":"https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9ad"},{"type":"FIX","url":"https://github.com/nmap/nmap/issues/1077"},{"type":"EVIDENCE","url":"https://github.com/nmap/nmap/issues/1227"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nmap/nmap","events":[{"introduced":"0"},{"fixed":"350bbe0597d37ad67abe5fef8fba984707b4e9ad"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-18594.json","vanir_signatures_modified":"2026-08-07T14:49:09Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"181885123553807210789057297674015574442","length":602},"id":"CVE-2017-18594-884d6df0","signature_type":"Function","signature_version":"v1","source":"https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9ad","target":{"function":"do_session_handshake","file":"nse_libssh2.cc"}},{"deprecated":false,"digest":{"line_hashes":["89047191141271898078379186729701011087","288418200066937758181363772380073444813","197504247299643829413881507450264840980","45853858347866020060594260890860214833","230612446715307993172166006795828895723","198393754361702321352110806437967051769","253764268990083538657657834154227694516","49832567131233925307305766627838607310","55587154207647647599364397019466709572","157468943989143697765082448397421470797","301199915657737667528034694382631924465"],"threshold":0.9},"id":"CVE-2017-18594-eec30225","signature_type":"Line","signature_version":"v1","source":"https://github.com/nmap/nmap/commit/350bbe0597d37ad67abe5fef8fba984707b4e9ad","target":{"file":"nse_libssh2.cc"}}]}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}