« Volver al listado

CVE-2006-2093

Estado: ModificadaBaja (2.6)—

Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter. NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script "can not do anything nasty." This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-2093",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "HIGH",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-04-29T10:02:00.000",
  "references": [
    {
      "url": "http://securityreason.com/securityalert/817",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1015996",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/25084",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431987/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431993/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431994/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1541",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26034",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://usn.ubuntu.com/279-1/",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/817",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1015996",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/25084",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431987/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431993/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/431994/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/1541",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26034",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://usn.ubuntu.com/279-1/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-399"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nessus before 2.2.8, and 3.x before 3.0.3, allows user-assisted attackers to cause a denial of service (memory consumption) via a NASL script that calls split with an invalid sep parameter.  NOTE: a design goal of the NASL language is to facilitate sharing of security tests by guaranteeing that a script \"can not do anything nasty.\"  This issue is appropriate for CVE only if Nessus users have an expectation that a split statement will not use excessive memory."
    }
  ],
  "lastModified": "2026-06-16T22:24:19.933",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nessus:nessus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "893B7354-62EB-470D-97F2-AED3A424B30D",
              "versionEndIncluding": "2.2.7"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "757C2A87-10EA-48A5-890E-1779FBFEE0A0",
              "versionEndIncluding": "3.0.2"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34121C2E-978F-4D68-969A-558886F29CF8"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.0_rc1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "53E34C0B-AAC7-4117-8E68-D32FEBB9ABCB"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DD466D6-094E-4F89-AA7E-8C958D751206"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10E2F716-1BE6-4F06-80A2-C03F60F58E3F"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B73F0FA-8454-4291-98D1-9F7A99373557"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "511BAE3E-16F4-4451-84D7-AAEB1FD3A87A"
            },
            {
              "criteria": "cpe:2.3:a:nessus:nessus:2.2.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BEF4E5AB-816A-4B1D-8901-6551C14B6688"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}