PT-2018-13586 · Nmap · Libnmap

Cris_Semmle

·

Published

2018-10-30

·

Updated

2019-10-09

·

CVE-2018-16461

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions libnmapp versions prior to 0.4.16 libnmap versions prior to 0.4.16
Description A command injection issue allows arbitrary commands to be executed via arguments to the range options. This can be exploited by passing malicious input to the range option, potentially leading to unauthorized command execution.
Recommendations For libnmapp versions prior to 0.4.16, update to version 0.4.16 or later. For libnmap versions prior to 0.4.16, update to version 0.4.16 or later. As a temporary workaround, consider restricting the use of the range option to minimize the risk of exploitation.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16461
GHSA-7G2W-6R25-2J7P

Affected Products

Libnmap