CVE-2020-8447: Use After Free
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a use-after-free during processing of syscheck formatted msgs (received from authenticated remote agents and delivered to the analysisd processing queue by ossec-remoted).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8447?
CVE-2020-8447 is classified as a high severity vulnerability due to the potential for exploitation in affected OSSEC versions.
How do I fix CVE-2020-8447?
To mitigate CVE-2020-8447, update OSSEC-HIDS to version 3.6.0 or later, as this version has addressed the vulnerability.
Which versions of OSSEC are affected by CVE-2020-8447?
OSSEC-HIDS versions from 2.7 through 3.5.0 are vulnerable to CVE-2020-8447.
What type of vulnerability is CVE-2020-8447?
CVE-2020-8447 is a use-after-free vulnerability found in the ossec-analysisd component during log analysis.
Can CVE-2020-8447 be exploited remotely?
Yes, CVE-2020-8447 can potentially be exploited remotely through authenticated connections by remote agents.