CVE-2020-8443: Buffer Overflow
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to an off-by-one heap-based buffer overflow during the cleaning of crafted syslog msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8443?
CVE-2020-8443 has been rated as a medium severity vulnerability due to its potential for exploitation through heap-based buffer overflow.
How do I fix CVE-2020-8443?
To fix CVE-2020-8443, upgrade the OSSEC-HIDS to version 3.5.1 or later to mitigate the off-by-one buffer overflow vulnerability.
What software versions are affected by CVE-2020-8443?
CVE-2020-8443 affects OSSEC-HIDS versions 2.7 through 3.5.0.
What kind of attack does CVE-2020-8443 enable?
CVE-2020-8443 enables a possible buffer overflow attack that can lead to arbitrary code execution.
Who is at risk for CVE-2020-8443?
Organizations using the affected versions of OSSEC-HIDS for log analysis are at risk of CVE-2020-8443.