PT-2020-20142 · Trend Micro · Ossec-Hids

·

CVE-2020-8442

·

Published

2020-01-30

·

Updated

2022-09-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSSEC-HIDS versions 2.7 through 3.5.0
Description The server component responsible for log analysis, ossec-analysisd, is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.
Recommendations For OSSEC-HIDS versions 2.7 through 3.5.0, consider restricting access to the ossec-analysisd component until a patch is available. As a temporary workaround, limit the interaction with the rootcheck decoder component to minimize the risk of exploitation.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8442

Affected Products

Ossec-Hids