
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-8445 affects OSSEC-HIDS versions 2.7 through 3.5.0. The vulnerability exists in the OS_CleanMSG function within ossec-analysisd, which fails to remove or encode terminal control characters or newlines from processed log messages (NVD, Debian Security).
The vulnerability lies in the OS_CleanMSG function of ossec-analysisd, which does not properly handle terminal control characters and newlines in processed log messages. These characters are subsequently logged without proper sanitization. The issue allows newlines (\n) to remain in messages processed by ossec-analysisd (GitHub Issue).
The vulnerability could enable two types of attacks: 1) The use of terminal control characters could allow attackers to obfuscate events or potentially execute commands when viewed through vulnerable terminal emulators, and 2) The presence of newlines in messages could allow injection of nested events into the OSSEC log, potentially misleading system administrators about actual alerts (GitHub Issue).
This vulnerability may be exploitable as an unauthenticated remote attack for certain types and origins of logged data. The attack surface is particularly relevant when an OSSEC agent is compromised, where the agent key and associated counters are known (GitHub Issue).
The vulnerability was addressed in OSSEC-HIDS version 3.6.0. Users are advised to upgrade to this version or later to mitigate the risk (Gentoo Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."