CVE-2003-0372

Severity CVSS v4.0:
Pending analysis
Type:
CWE-189 Numeric Errors
Publication date:
16/06/2003
Last modified:
03/04/2025

Description

Signed integer vulnerability in libnasl in Nessus before 2.0.6 allows local users with plugin upload privileges to cause a denial of service (core dump) and possibly execute arbitrary code by causing a negative argument to be provided to the insstr function as used in a NASL script.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nessus:nessus:*:*:*:*:*:*:*:* 2.0.5 (including)