peter bassill · operator
$ cve CVE-2014-5284 JSON

CVE-2014-5284 EXPLOIT

7.2
HIGH · CVSS 2.0 · EPSS 2.4% (pctl 84)

Patch early

A public exploit exists.

Description

host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.

Scoring

CVSS7.2 (HIGH, v2.0)
VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS2.43% — more likely to be exploited than 84% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2014-12-02
Last modified2026-06-17

Affected (1)

VendorProduct
ossecossec

Public exploits

SourceTitleDate
exploit-dbOSSEC 2.8 - 'hosts.deny' Local Privilege Escalation2014-11-14

References

→ the Explorer  ·  watch your stack  ·  NVD