ALAS2-2023-2333

Related Vulnerabilities: CVE-2018-15173  

Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service. (CVE-2018-15173)

ALAS2-2023-2333


Amazon Linux 2 Security Advisory: ALAS-2023-2333
Advisory Release Date: 2023-10-30 23:59 Pacific
Advisory Updated Date: 2023-11-01 22:22 Pacific
Severity: Low

Issue Overview:

Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service. (CVE-2018-15173)


Affected Packages:

nmap


Issue Correction:
Run yum update nmap to update your system.

New Packages:
aarch64:
    nmap-6.40-19.amzn2.0.1.aarch64
    nmap-ncat-6.40-19.amzn2.0.1.aarch64
    nmap-debuginfo-6.40-19.amzn2.0.1.aarch64

i686:
    nmap-6.40-19.amzn2.0.1.i686
    nmap-ncat-6.40-19.amzn2.0.1.i686
    nmap-debuginfo-6.40-19.amzn2.0.1.i686

noarch:
    nmap-frontend-6.40-19.amzn2.0.1.noarch

src:
    nmap-6.40-19.amzn2.0.1.src

x86_64:
    nmap-6.40-19.amzn2.0.1.x86_64
    nmap-ncat-6.40-19.amzn2.0.1.x86_64
    nmap-debuginfo-6.40-19.amzn2.0.1.x86_64