PT-2006-3073 · Tenable · Nessus

Publicado

2006-04-29

·

Atualizado

2018-10-18

·

CVE-2006-2093

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Nessus versions prior to 2.2.8 Nessus versions 3.x prior to 3.0.3
Description The issue allows user-assisted attackers to cause a denial of service via a NASL script that calls the split function with an invalid sep parameter. This could lead to excessive memory consumption. The NASL language is designed to guarantee that a script cannot perform malicious actions, but in this case, the expectation that a split statement will not use excessive memory may not be met.
Recommendations For Nessus versions prior to 2.2.8, update to version 2.2.8 or later. For Nessus versions 3.x prior to 3.0.3, update to version 3.0.3 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-2093

Produtos afetados

Nessus