CVE-2015-3222: High severity ossec vulnerability
Published Sep 7, 2017
·Updated
syscheck/seechanges.c in OSSEC 2.7 through 2.8.1 on NIX systems allows local users to execute arbitrary code as root.
Affected Software
4 affected components
OSSEC OSSEC=2.7.0
OSSEC OSSEC=2.7.1
OSSEC OSSEC=2.8.0
OSSEC OSSEC=2.8.1
Event History
Sep 7, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-3222?
CVE-2015-3222 is classified as a high-severity vulnerability due to its potential to allow local users to execute arbitrary code as root.
2
How can I mitigate CVE-2015-3222?
To mitigate CVE-2015-3222, it's recommended to upgrade to a patched version of OSSEC that is not vulnerable.
3
Which OSSEC versions are affected by CVE-2015-3222?
CVE-2015-3222 affects OSSEC versions 2.7.0, 2.7.1, 2.8.0, and 2.8.1.
4
What type of attacks can exploit CVE-2015-3222?
CVE-2015-3222 can be exploited for local privilege escalation, allowing attackers to gain root access.
5
Is CVE-2015-3222 being actively exploited in the wild?
There is no public information confirming active exploitation of CVE-2015-3222, but its high severity warrants prompt remediation.