2.6
CVSSv2

CVE-2006-2093

Published: 29/04/2006 Updated: 18/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P

Vulnerability Summary

Nessus prior to 2.2.8, and 3.x prior to 3.0.3, allows user-assisted malicious users to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory.

Vulnerable Product Search on Vulmon Subscribe to Product

nessus nessus 2.2.2

nessus nessus 2.2.3

nessus nessus 2.2.0_rc1

nessus nessus 2.2.1

nessus nessus 2.2.0

nessus nessus

nessus nessus 2.2.5

nessus nessus 2.2.6

Vendor Advisories

Jayesh KS discovered that the nasl_split() function in the NASL (Nessus Attack Scripting Language) library did not check for a zero-length separator argument, which lead to an invalid memory allocation This library is primarily used in the Nessus security scanner; a remote attacker could exploit this vulnerability to cause the Nessus daemon to cra ...