CVE-2020-8445
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (
) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.
En OSSEC-HIDS versiones 2.7 hasta 3.5.0, la función OS_CleanMSG en ossec-analysisd no elimina ni codifica caracteres de control de terminal o nuevas líneas de mensajes de registro procesados. En muchos casos, esos caracteres son registrados luego. Debido a que nuevas líneas (
) son permitidas en los mensajes procesados ??por ossec-analysisd, puede ser posible inyectar eventos anidados en el registro de ossec. El uso de caracteres de control de terminal puede permitir eventos de ofuscación o ejecutar comandos cuando se visualizaron por medio de emuladores de terminal vulnerables. Este puede ser un ataque remoto no autenticado para ciertos tipos y orígenes de datos registrados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-30 CVE Reserved
- 2020-01-30 CVE Published
- 2024-08-04 CVE Updated
- 2024-09-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/ossec/ossec-hids/issues/1814 | Third Party Advisory | |
https://github.com/ossec/ossec-hids/issues/1821 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://security.gentoo.org/glsa/202007-33 | 2022-09-12 | |
https://www.ossec.net | 2022-09-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ossec Search vendor "Ossec" | Ossec Search vendor "Ossec" for product "Ossec" | >= 2.7 <= 3.5.0 Search vendor "Ossec" for product "Ossec" and version " >= 2.7 <= 3.5.0" | - |
Affected
|