CVE-2020-8445

CRITICAL

OSSEC-HIDS <3.5.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://github.com/ossec/ossec-hids/issues/1821
Vendor Advisory x_refsource_misc
https://www.ossec.net/
Third Party Advisory x_refsource_misc
https://github.com/ossec/ossec-hids/issues/1814
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202007-33

Scores

CVSS v3 9.8
EPSS 0.0228
EPSS Percentile 81.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
ossec/ossec 2.7 - 3.5.0
Published Jan 30, 2020
Tracked Since Feb 18, 2026