CVE-2021-28040: High severity ossec vulnerability
An issue was discovered in OSSEC 3.6.0. An uncontrolled recursion vulnerability in osxml.c occurs when a large number of opening and closing XML tags is used. Because recursion is used in ReadElem without restriction, an attacker can trigger a segmentation fault once unmapped memory is reached.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28040?
CVE-2021-28040 has a high severity due to its potential to cause a denial of service through a segmentation fault.
How do I fix CVE-2021-28040?
To fix CVE-2021-28040, update to a patched version of OSSEC that controls recursion in XML processing.
What systems are affected by CVE-2021-28040?
CVE-2021-28040 specifically affects OSSEC version 3.6.0.
What kind of attack does CVE-2021-28040 facilitate?
CVE-2021-28040 facilitates a denial of service attack through uncontrolled recursion in XML parsing.
Can CVE-2021-28040 lead to data breaches?
While CVE-2021-28040 primarily leads to service disruption, it does not directly allow for unauthorized data access.