CVE-2020-8448: Null Pointer Dereference
Published Jan 30, 2020
·Updated
In OSSEC-HIDS 2.7 through 3.5.0, the server component responsible for log analysis (ossec-analysisd) is vulnerable to a denial of service (NULL pointer dereference) via crafted messages written directly to the analysisd UNIX domain socket by a local user.
Affected Software
1 affected component
OSSEC OSSEC>=2.7<=3.5.0
Event History
Jan 30, 2020
CVE Published
via MITRE·12:32 AM
Data Sourced
via MITRE·12:32 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8448?
CVE-2020-8448 is classified as a high-severity vulnerability due to its potential for denial of service.
2
How do I fix CVE-2020-8448?
To mitigate CVE-2020-8448, update your OSSEC-HIDS to a version greater than 3.5.0.
3
Who is affected by CVE-2020-8448?
CVE-2020-8448 affects OSSEC-HIDS versions from 2.7 to 3.5.0.
4
What type of vulnerability is CVE-2020-8448?
CVE-2020-8448 is a denial of service vulnerability caused by a NULL pointer dereference.
5
Can CVE-2020-8448 be exploited remotely?
CVE-2020-8448 cannot be exploited remotely as it requires local access to the analysisd UNIX domain socket.