CVE-2014-5284 describes a local privilege escalation vulnerability in OSSEC versions prior to 2.8.1. The host-deny.sh script insecurely creates temporary files with predictable names, allowing a local attacker to pre-create these files and manipulate access restrictions in hosts.deny, ultimately gaining root privileges. This vulnerability has a CVSS score of 7.2, indicating high severity with complete confidentiality, integrity, and availability impacts, and requires local access. While not actively exploited in the wild, public exploit code exists, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.8.0CPE matchmatch criteria | cpe:2.3:a:ossec:ossec:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.