First published: Fri Jun 06 2003(Updated: )
Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tenable Nessus | <=2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0372 is classified as a medium severity vulnerability that can lead to denial of service or potential arbitrary code execution.
To address CVE-2003-0372, you should upgrade Nessus to version 2.0.6 or later.
Nessus versions prior to 2.0.6, specifically up to 2.0.5, are affected by CVE-2003-0372.
CVE-2003-0372 allows local users with plugin upload privileges to cause denial of service or potentially execute arbitrary code.
Local users on systems running vulnerable versions of Nessus are exposed to CVE-2003-0372.