Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OpenSSL 3.0.5 high severity findings. #2575

Closed
miloslav-zadrazil-solarwinds opened this issue Dec 1, 2022 · 3 comments
Closed

OpenSSL 3.0.5 high severity findings. #2575

miloslav-zadrazil-solarwinds opened this issue Dec 1, 2022 · 3 comments
Labels
Nmap question security Possibly security-relevant

Comments

@miloslav-zadrazil-solarwinds

Describe the bug
Vulnerability scans on nmap release shows high severity issue of OpenSSL 3.0.5 version

  • X.509 Email Address 4-byte Buffer Overflow (CVE-2022-3602)
  • X.509 Email Address Variable Length Buffer Overflow (CVE-2022-3786)
    could you, please provide me with information whether nmap is affected by those vulnerabilities ?
@dmiller-nmap
Copy link

Nmap is not affected by these vulnerabilities because Nmap does not perform certificate validation. Ncat, when the --ssl-verify option is used, may be vulnerable.

@fyodor
Copy link
Member

fyodor commented Dec 2, 2022

Just to add one more thing...even though Nmap itself isn't vulnerable, we'll be updating to the patched OpenSSL in the next release. We understand that nobody wants these "vulnerable" OpenSSL DLL's on their system even if they can't technically be exploited. They can still lead to alerts from vulnerability scanners, etc. Thanks @miloslav-zadrazil-solarwinds for the report, and of course @dmiller-nmap for researching the CVE's so quickly.

@miloslav-zadrazil-solarwinds
Copy link
Author

Excellent and very helpful . Many thanks for quick response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Nmap question security Possibly security-relevant
Projects
None yet
Development

No branches or pull requests

3 participants