Uncontrolled Recursion in OSSEC HIDS by OSSEC
CVE-2021-28040

7.5HIGH

Key Information:

Vendor

Ossec

Status
Vendor
CVE Published:
5 March 2021

What is CVE-2021-28040?

An issue in OSSEC HIDS version 3.6.0 arises from an uncontrolled recursion vulnerability found in the XML processing functionality. This issue occurs when a large number of XML tags are present, leading the system to process them without any restrictions. An attacker can exploit this vulnerability, causing the application to reach unmapped memory which results in a segmentation fault. This vulnerability can lead to service disruptions and should be addressed promptly.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.