Lucene search

K
ubuntuUbuntuUSN-279-1
HistoryMay 04, 2006 - 12:00 a.m.

libnasl/nessus vulnerability

2006-05-0400:00:00
ubuntu.com
29

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%

Releases

  • Ubuntu 5.10
  • Ubuntu 5.04

Details

Jayesh KS discovered that the nasl_split() function in the NASL
(Nessus Attack Scripting Language) library did not check for a
zero-length separator argument, which lead to an invalid memory
allocation. This library is primarily used in the Nessus security
scanner; a remote attacker could exploit this vulnerability to cause
the Nessus daemon to crash.

OSVersionArchitecturePackageVersionFilename
Ubuntu5.10noarchlibnasl2< *UNKNOWN
Ubuntu5.04noarchlibnasl2< *UNKNOWN

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

6.3 Medium

AI Score

Confidence

High

0.053 Low

EPSS

Percentile

93.1%