Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Nessus 拒绝服务漏洞
Vulnerability Description
Nessus 2.2.8之前的版本以及3.0.3之前的3.x系列版本允许用户辅助攻击者借助于NASL脚本(利用无效的sep参数调用split)造成拒绝服务(内存消耗)。注:NASL语言的设计目标是在确保脚本不能执行恶意操作的前提下简化安全测试的共享。只要Nessus用户期望分割语句不使用过大的内存。
CVSS Information
N/A
Vulnerability Type
N/A