CVE-2020-8442: Buffer Overflow
Published Jan 30, 2020
·Updated
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a heap-based buffer overflow in the rootcheck decoder component via an authenticated client.
Affected Software
1 affected component
OSSEC OSSEC>=2.7<=3.5.0
Remediation
Patch Available
Event History
Jan 30, 2020
CVE Published
via MITRE·12:34 AM
Data Sourced
via MITRE·12:34 AM
Description
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability CVE-2020-8442?
CVE-2020-8442 is a heap-based buffer overflow vulnerability in the rootcheck decoder component of OSSEC-HIDS 2.7 through 3.5.0.
2
How severe is the vulnerability CVE-2020-8442?
The severity of CVE-2020-8442 is high, with a CVSS score of 8.8.
3
Which software versions are affected by CVE-2020-8442?
OSSEC-HIDS versions 2.7 through 3.5.0 are affected by CVE-2020-8442.
4
How can I fix the vulnerability CVE-2020-8442?
To fix CVE-2020-8442, you should update OSSEC-HIDS to a version higher than 3.5.0.
5
Where can I find more information about CVE-2020-8442?
You can find more information about CVE-2020-8442 on the official GitHub page for OSSEC-HIDS and the Gentoo Security Advisory.