Vulnerabilities > CVE-2003-0372 - Numeric Errors vulnerability in Nessus

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
nessus
CWE-189
exploit available

Summary

Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.

Vulnerable Configurations

Part Description Count
Application
Nessus
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionNessus 2.0.x LibNASL Arbitrary Code Execution Vulnerability. CVE-2003-0372. Dos exploits for multiple platform
idEDB-ID:22634
last seen2016-02-02
modified2003-05-22
published2003-05-22
reporterSir Mordred
sourcehttps://www.exploit-db.com/download/22634/
titleNessus 2.0.x LibNASL Arbitrary Code Execution Vulnerability