Логотип exploitDog
bind:CVE-2020-8445
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-8445

Количество 3

Количество 3

nvd логотип

CVE-2020-8445

около 6 лет назад

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-8445

около 6 лет назад

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-ana ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9vhf-xgg9-m6cf

больше 3 лет назад

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-8445

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

CVSS3: 9.8
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-8445

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-ana ...

CVSS3: 9.8
1%
Низкий
около 6 лет назад
github логотип
GHSA-9vhf-xgg9-m6cf

In OSSEC-HIDS 2.7 through 3.5.0, the OS_CleanMSG function in ossec-analysisd doesn't remove or encode terminal control characters or newlines from processed log messages. In many cases, those characters are later logged. Because newlines (\n) are permitted in messages processed by ossec-analysisd, it may be possible to inject nested events into the ossec log. Use of terminal control characters may allow obfuscating events or executing commands when viewed through vulnerable terminal emulators. This may be an unauthenticated remote attack for certain types and origins of logged data.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу