← Voltar para CVEs
CVE-2020-8445
CRITICAL9.8
Descricao
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.
Detalhes CVE
Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado1/30/2020
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0
Produtos afetados
ossec:ossec
Fraquezas (CWE)
CWE-20
Referencias
https://github.com/ossec/ossec-hids/issues/1814(cve@mitre.org)
https://github.com/ossec/ossec-hids/issues/1821(cve@mitre.org)
https://security.gentoo.org/glsa/202007-33(cve@mitre.org)
https://www.ossec.net/(cve@mitre.org)
https://github.com/ossec/ossec-hids/issues/1814(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/ossec/ossec-hids/issues/1821(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202007-33(af854a3a-2127-422b-91ae-364da2661108)
https://www.ossec.net/(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.