CVE-2018-1000161

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000161
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1000161.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-1000161
Related
Published
2018-04-18T19:29:00Z
Modified
2024-11-21T03:39:49Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

References

Affected packages

Debian:11 / nmap

Package

Name
nmap
Purl
pkg:deb/debian/nmap?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.70+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / nmap

Package

Name
nmap
Purl
pkg:deb/debian/nmap?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.70+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / nmap

Package

Name
nmap
Purl
pkg:deb/debian/nmap?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7.70+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}