#VU102308 Path traversal in OSSEC - CVE-2020-8446
Published: January 6, 2025
OSSEC
OSSEC Project
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to input validation error when processing directory traversal sequences inside syscheck messages. A local user can write a specially crafted message directly to the analysisd UNIX domain socket and overwrite arbitrary files on the system.